Ransomware Attack on Wealth Depot LLC by Everest Ransomware Group

Incident Date:

May 15, 2024

World map

Overview

Title

Ransomware Attack on Wealth Depot LLC by Everest Ransomware Group

Victim

Wealth Depot LLC

Attacker

Everest

Location

Newton, USA

New Jersey, USA

First Reported

May 15, 2024

Ransomware Attack on Wealth Depot LLC by Everest Ransomware Group

Victim Overview

Wealth Depot LLC, a financial planning and wealth management company based in New Jersey, USA, was targeted by the Everest Ransomware Group. The company specializes in personalized investment strategies, retirement planning, and estate planning services. Wealth Depot stands out in the finance sector for its focus on helping individuals and families achieve their financial goals through a range of financial products and services.

Company Profile

The company has fewer than 25 employees and an estimated revenue of less than $5 million. The company offers services such as defining new business approaches, improving customer service plans, training staff, and providing outsourced accounting services to owners of service businesses.

Attack Details

The ransomware attack on Wealth Depot resulted in approximately 450 GB of data being stolen by the Everest Ransomware Group. The victim's website was compromised in the attack. While no specific ransom demand was mentioned, the severity of the attack raises concerns about the potential impact on the company's operations and data security.

Ransomware Group Overview

The Everest Ransomware Group is a notorious cybercriminal organization known for ransomware attacks, data exfiltration, and initial access brokering. The group targets organizations across various industries and regions, with a particular focus on the Americas and sectors like capital goods, health, and the public sector.

Penetration Tactics

Everest ransomware utilizes compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement within the victim's systems. The ransomware encrypts files using AES and DES algorithms, appending the “.EVEREST” extension to the encrypted files. The attackers then demand a ransom payment in exchange for the decryption key.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.