Ransomware Hits Red Barrels Disrupting Game Development Plans

Incident Date:

October 3, 2024

World map

Overview

Title

Ransomware Hits Red Barrels Disrupting Game Development Plans

Victim

Red Barrels

Attacker

Nitrogen

Location

Montreal, Canada

, Canada

First Reported

October 3, 2024

Ransomware Attack on Red Barrels: A Deep Dive into the Nitrogen Group's Latest Exploit

Sources

Red Barrels, a Montreal-based independent video game development studio, has recently fallen victim to a ransomware attack orchestrated by the notorious Nitrogen group. Known for its acclaimed horror franchise, *Outlast*, Red Barrels has captivated over 37 million players worldwide with its immersive and terrifying gaming experiences. Founded in 2011 by former Ubisoft developers, the studio has maintained its independence, allowing for creative freedom in its projects.

The attack, which resulted in the exfiltration of approximately 1.8 terabytes of sensitive data, has significantly disrupted Red Barrels' production timeline. The company, employing around 72 individuals, has been forced to delay its roadmap, including the anticipated release of *The Outlast Trials*. Despite the breach, Red Barrels has assured its community that players have not been affected, emphasizing its commitment to safeguarding information and adapting to the evolving cyber threat landscape.

The Nitrogen ransomware group, known for its sophisticated malware campaigns, primarily targets IT professionals and organizations through deceptive advertising and social engineering tactics. The group has been linked to various ransomware attacks, including the infamous BlackCat/ALPHV ransomware. Nitrogen distinguishes itself by employing advanced techniques such as DLL sideloading and leveraging frameworks like Sliver and Cobalt Strike for post-exploitation activities.

In the case of Red Barrels, the Nitrogen group likely penetrated the company's systems through malicious advertisements, leading victims to download compromised software. Once access was gained, the attackers conducted data exfiltration before deploying the ransomware payload. This incident highlights the vulnerabilities faced by independent studios like Red Barrels, which may lack the extensive cybersecurity resources of larger organizations.

Red Barrels has responded to the breach by engaging an external team of cybersecurity experts to conduct a thorough investigation. The company has also informed relevant stakeholders and authorities about the incident and offered support to its employees. As Red Barrels continues to focus on the future of its upcoming projects, it remains dedicated to creating unforgettable gaming experiences while navigating the challenges posed by cyber threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.