AI DevwWrld CyberDSA Chatbot Summit Cyber Revolution Summit CYSEC Global Cyber Security & Cloud Expo World Series Digital Identity & Authentication Summit Asian Integrated Resort Expo Middle East Low Code No Code Summit TimeAI Summit

MGM ESXi servers encrypted by ransomware attack: BlackCat group held responsible

MGM Resorts hit by ransomware attack: cybersecurity implications and business repercussions

According to reliable sources, MGM's ESXi servers were encrypted by a ransomware attack conducted by the BlackCat/ALPHV group. The Scattered Spider group is suspected of using several types of social engineering attacks.

This pill is also available in Italian language

MGM's ESXi servers were reportedly encrypted in a ransomware attack, according to reliable sources. The BlackCat Group, also known as APLHV, is believed to be responsible for this attack which disrupted MGM Resorts' operations, forcing the company to shut down its IT systems.

Ransomware executed and MGM data stolen

Research by cybersecurity experts reveals that cybercriminals affiliated with the ALPHV ransomware group, known as BlackCat, allegedly breached MGM through a social engineering attack. Although it has not been confirmed, the administrator of BlackCat/ALPHV revealed that one of their "adverts" (affiliates) carried out the attack on MGM, but denied that it was the same actor who hacked Western Digital last March.

Scattered Spider: the group behind the attacks

Scattered Spider is a cybercriminal group suspected of using a wide range of social engineering attacks to compromise corporate networks. These attacks include impersonating help desk staff to trick users into providing their credentials, SIM swap attacks to take control of a targeted mobile device's phone number, and phishing and MFA fatigue attacks to gain access to multi-factor authentication codes.

Scattered Spider's attack method

Once threat actors have compromised a network, they have been shown to use Bring Your Own Vulnerable Driver attacks to gain elevated access to a compromised device. This access is then used to spread laterally across the network, steal data, and ultimately gain access to administration credentials. Recently, they have started carrying out ransomware attacks using the BlackCat/ALPHV ransomware to encrypt devices. The ransomware component is a new tactic for the group, which usually engages in extortion by demanding millions in ransoms to not disclose data or to receive a decryptor.

Follow us on Facebook for more pills like this

09/17/2023 13:41

Editorial AI

Complementary pills

Las Vegas casinos double violations: Scattered Spider and ALPHV ChargedAn unprecedented hacking operation puts the security of Las Vegas casinos at risk

Last pills

Serious vulnerability discovered in Rabbit R1: all user data at riskVulnerability in Rabbit R1 exposes sensitive API keys. What are the privacy risks?

Cyber attack in Indonesia: the new Brain Cipher ransomware brings services to their kneesNew ransomware hits Indonesia: learn how Brain Cipher crippled essential services and the techniques used by hackers

Patelco Credit Union: security incident halts customer services in CaliforniaService disruption and customer frustration: Patelco Credit Union works to resolve security incident

Cyber attack on TeamViewer: immediate response and investigations underwayStrengthened security measures and international collaborations to counter the cyber threat