Ransomware Attack on MS Ultrasonic by Hunters International: 3.7 TB Data Exfiltrated
Incident Date:
July 15, 2024
Overview
Title
Ransomware Attack on MS Ultrasonic by Hunters International: 3.7 TB Data Exfiltrated
Victim
MS Ultrasonic Technology Group
Attacker
Hunters International
Location
First Reported
July 15, 2024
Ransomware Attack on MS Ultrasonic Technology Group by Hunters International
Company Overview
MS Ultrasonic Technology Group, headquartered in Germany, is a leading provider of ultrasonic welding solutions. Founded in 1965, the company specializes in ultrasonic welding of plastics, offering a range of products including custom machines, series machines, and modular systems for various industries such as automotive, packaging, textiles, medical technology, and consumer goods. With a revenue of $257 million, MS Ultrasonic is recognized for its innovative ultrasonic processes and global presence, with locations in Germany, the USA, Brazil, and China.
Attack Overview
On October 2023, MS Ultrasonic Technology Group fell victim to a ransomware attack orchestrated by the cybercriminal group Hunters International. The attackers claim to have infiltrated the company's systems, exfiltrating 3.7 TB of sensitive data. They have threatened to publish this data within 3-4 days if their ransom demands are not met, putting the company's operations and confidential information at significant risk.
About Hunters International
Hunters International is a Ransomware-as-a-Service (RaaS) group that emerged in Q3 of 2023, shortly after the disruption of the Hive ransomware group. The group exhibits significant technical overlap with Hive, suggesting an evolution or offshoot of the dismantled operation. Hunters International focuses on data exfiltration and extortion, targeting victims across various regions without a specific focus on particular industries. The group has been linked to Nigeria through domain registrations and email addresses, although they use deceptive methods to conceal their true origins.
Penetration and Vulnerabilities
The exact method of penetration used by Hunters International to infiltrate MS Ultrasonic's systems remains unclear. However, given the group's technical lineage and tactics, it is likely that they employed sophisticated phishing attacks, exploiting vulnerabilities in the company's cybersecurity infrastructure. The attack underscores the importance of robust cybersecurity measures, especially for companies like MS Ultrasonic that handle large volumes of sensitive data and operate in critical manufacturing sectors.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.