suncrypt attacks Migros

Incident Date:

March 16, 2022

World map

Overview

Title

suncrypt attacks Migros

Victim

Migros

Attacker

Suncrypt

Location

Haydar, Turkey

Merkez/KahramanmaraÅŸ, Turkey

First Reported

March 16, 2022

Migros, a Retail Giant, Targeted by SunCrypt Ransomware Group

Company Overview

Migros, a leading retail company in Turkey with over 100,000 employees, has been targeted by the SunCrypt ransomware group. The attack was confirmed through a leak on the group's dark web site, which also revealed that the company's website is https://www.migros.com.tr/.

Migros is a significant player in the retail sector, with a wide range of products and services. The company's website provides information on their products, services, and locations, indicating a strong online presence and potential vulnerabilities to cyber threats.

Vulnerabilities and Targeting

SunCrypt, a ransomware-as-a-service (RaaS) operation, has been active since mid-2020 and is known for its triple extortion tactics, including file encryption, threat to publish stolen data, and distributed denial of service (DDoS) attacks on non-paying victims. The group has been targeting high-value entities, keeping ransom payment negotiations private to avoid law enforcement attention and media coverage.

SunCrypt's Capabilities

The 2022 SunCrypt variant includes new capabilities such as process termination, stopping services, and wiping the machine clean for ransomware execution. These features have been present in other ransomware strains but are recent additions to SunCrypt, suggesting that the group is still in an early development phase.

Impact and Response

The attack on Migros is part of SunCrypt's ongoing operations, which have been described as stagnant but still a real threat. The company's response to the attack is not publicly available, but it is likely that they are taking steps to mitigate the damage and prevent further attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.