Ransomware Attack on Wealth Depot LLC by Everest Ransomware Group
Incident Date:
May 15, 2024
Overview
Title
Ransomware Attack on Wealth Depot LLC by Everest Ransomware Group
Victim
Wealth Depot LLC
Attacker
Everest
Location
First Reported
May 15, 2024
Ransomware Attack on Wealth Depot LLC by Everest Ransomware Group
Victim Overview
Wealth Depot LLC, a financial planning and wealth management company based in New Jersey, USA, was targeted by the Everest Ransomware Group. The company specializes in personalized investment strategies, retirement planning, and estate planning services. Wealth Depot stands out in the finance sector for its focus on helping individuals and families achieve their financial goals through a range of financial products and services.
Company Profile
The company has fewer than 25 employees and an estimated revenue of less than $5 million. The company offers services such as defining new business approaches, improving customer service plans, training staff, and providing outsourced accounting services to owners of service businesses.
Attack Details
The ransomware attack on Wealth Depot resulted in approximately 450 GB of data being stolen by the Everest Ransomware Group. The victim's website was compromised in the attack. While no specific ransom demand was mentioned, the severity of the attack raises concerns about the potential impact on the company's operations and data security.
Ransomware Group Overview
The Everest Ransomware Group is a notorious cybercriminal organization known for ransomware attacks, data exfiltration, and initial access brokering. The group targets organizations across various industries and regions, with a particular focus on the Americas and sectors like capital goods, health, and the public sector.
Penetration Tactics
Everest ransomware utilizes compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement within the victim's systems. The ransomware encrypts files using AES and DES algorithms, appending the “.EVEREST” extension to the encrypted files. The attackers then demand a ransom payment in exchange for the decryption key.
Sources:
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.