Rhysida Ransomware Strikes MYC Media, Demands Bitcoin
Incident Date:
July 7, 2024
Overview
Title
Rhysida Ransomware Strikes MYC Media, Demands Bitcoin
Victim
MYC Media
Attacker
Rhysida
Location
First Reported
July 7, 2024
Analysis of the Rhysida Ransomware Attack on MYC Media
Company Profile: MYC Media
MYC Media, a digital and print marketing agency based in Northern Ireland, has carved a niche in the Media & Internet sector with its comprehensive range of services aimed at enhancing the online presence of businesses. Established as MYC MEDIA PRIVATE (N.I.) LIMITED, the company offers services including search engine optimization, social media marketing, content creation, email marketing, and web design and development. With a strong presence on platforms like LinkedIn and positive employee feedback on Glassdoor, MYC Media is recognized for its supportive work environment and professional acumen in handling diverse digital marketing needs.
Details of the Ransomware Attack
On July 7, 2024, MYC Media fell victim to a targeted ransomware attack by the emerging cybercriminal group Rhysida. The attackers demanded a ransom of 5 bitcoins and set a deadline of six days. Rhysida's approach in this incident involved threatening to sell the stolen data exclusively to a single buyer, highlighting a severe risk of identity theft, financial fraud, and reputational damage to MYC Media. Despite these threats, the functionality of MYC Media's website post-attack raises questions about the veracity of the attackers' claims.
Rhysida Ransomware Group Profile
The Rhysida Ransomware Group, noted for its activities since May 2023, targets sectors like education, healthcare, and government, employing sophisticated tools such as the ChaCha20 encryption algorithm and a double extortion technique. This group is known for its strategic use of phishing campaigns to deploy ransomware and its preference for Bitcoin as the ransom payment method. Rhysida's operational tactics include leveraging valid credentials and VPNs for initial access, followed by the use of tools like PsExec for lateral movement within the network.
Potential Vulnerabilities and Entry Points
Considering MYC Media's extensive digital footprint, the company's significant online activities could have exposed them to increased cybersecurity risks. The nature of digital marketing, involving constant online engagement and data handling, might have made MYC Media an attractive target for Rhysida. The entry point for the ransomware could have been through phishing emails, given Rhysida's known tactics, or possibly through compromised network credentials, allowing the attackers to infiltrate MYC Media's systems and deploy the ransomware.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.