Rhysida Ransomware Strikes SSTech: Software Sector Alert

Incident Date:

April 3, 2024

World map

Overview

Title

Rhysida Ransomware Strikes SSTech: Software Sector Alert

Victim

Seven Seas Technology

Attacker

Rhysida

Location

Dubai, United Arab Emirates

, United Arab Emirates

First Reported

April 3, 2024

Rhysida Ransomware Attacks Seven Seas Technology

Company Overview

Rhysida, a new ransomware-as-a-service (RaaS) group, has claimed responsibility for an attack on Seven Seas Technology (SSTech), a leading system integrator and ICT solution provider in the UAE. The attack was announced on the group's dark web leak site, which also revealed that SSTech operates in the Software sector.

Seven Seas Technology is a well-established company with over 40 years of experience in the IT industry. They have a team of over 300 ICT trained and certified professionals, and they cater to over 1000 companies. SSTech is known for its collaborative, multi-cloud strategy and its focus on customer satisfaction. They offer a range of services, including Enterprise Systems, Cloud Offerings, Data Networking & Information Security, Unified Communication, Microsoft Licensing & Solutions, Value Added Services, BCP & DR, Data Centers, Cabling, Audio Visual, Access Control, CCTV, and Outsourcing Services.

Vulnerabilities and Targeting

The ransonware group Rhysida primarily targets the education, government, manufacturing, and technology and managed service provider sectors, but they have also been observed attacking the Healthcare and Public Health (HPH) sector. The group uses phishing attacks and Cobalt Strike to breach targets' networks and deploy their payloads.

The attack on Seven Seas Technology highlights the need for organizations to be vigilant against ransomware attacks, particularly those that exploit vulnerabilities in cloud services and hybrid IT environments.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.