Ransomware Attack on Rio Technologies LTD by Arcus Media

Incident Date:

May 24, 2024

World map

Overview

Title

Ransomware Attack on Rio Technologies LTD by Arcus Media

Victim

RIO TECHNOLOGY

Attacker

Arcus Media

Location

Bogotá, Colombia

, Colombia

First Reported

May 24, 2024

Ransomware Attack on Rio Technologies LTD by Arcus Media

Victim Overview

Rio Technologies LTD, a data technology company based in New York City, USA, was targeted in a ransomware attack by the relatively new threat actor, Arcus Media. The company specializes in simplifying decision-making through innovative data-driven solutions and has a revenue of $1 million. With 11-50 employees, Rio Technologies LTD stands out in the industry for its focus on leveraging technology, information, and the internet to provide cutting-edge solutions.

Attack Details

Arcus Media, known for conducting direct and double extortion methods, targeted Rio Technologies LTD as part of their 11 attacks since their discovery in May 2024. The group uses phishing emails with malicious attachments to gain initial access, deploys custom ransomware binaries, and employs obfuscation techniques to evade detection. They also establish persistence on infected systems and use credential dumping tools for privilege escalation.

Ransomware Group Overview

Arcus Media operates as a Ransomware-as-a-Service (RaaS) model, allowing other threat actors to use their malware while taking a cut of the profits. The group has targeted various sectors globally, including government, banking, finance, healthcare, and education. Arcus Media distinguishes itself with a unique affiliate program where new affiliates must be referred by a trusted affiliate and vetted to participate.

Attack Vector

Arcus Media could have penetrated Rio Technologies LTD's systems through phishing emails with malicious attachments, exploiting vulnerabilities in the company's network security. By deploying custom ransomware binaries and obfuscation techniques, the group was able to encrypt the company's data and demand a ransom for decryption.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.