Post

RansomHouse Picks a Fight with Namibia's Defense Establishment

RansomHouse Picks a Fight with Namibia's Defense Establishment

RansomHouse Picks a Fight with Namibia’s Defense Establishment 🚨

Namibia’s computer security incident response team has confirmed unauthorized activity in the defense ministry’s network, linking it to the notorious RansomHouse cybercrime group. In an unusually direct attribution, NAM-CSIRT named the group after RansomHouse listed the supposed victim on its leak site on September 16. RansomHouse identified the victim as the “Namibian Defence Force,” although the domain in its listing belongs to the Ministry of Defence and Veterans Affairs (MODVA), the government department overseeing the military.

RansomHouse’s website stated: “Dear management of Namibian Defence Force. We were waiting for you for quite some time, but it seems that your IT department decided to conceal the incident that took place in your company. We strongly recommend you to contact us to prevent your confidential data and project documents from being leaked.” The listing treated the target as a company with $434 million in annual revenue, but NAM-CSIRT subsequently confirmed unauthorized activity within MODVA’s network.

NAM-CSIRT said in a statement: “Analysis of the affected systems established that the incident is associated with the RansomHouse ransomware group, a cybercriminal syndicate known internationally for deploying ransomware and engaging in so-called double extortion tactics where threat actors encrypt systems while simultaneously threatening to disclose alleged stolen information. NAM-CSIRT remains actively engaged in coordinating technical support, investigation activities, remediation measures, and post-incident reviews in line with the National Incident Management framework outlined in the National Cyber Security Incident Management guidelines.”

NAM-CSIRT did not answer The Register’s questions about the expected recovery timeline, whether a ransom had been demanded, or whether any payment was under consideration. It has not disclosed which systems or data were affected, whether information was stolen, or whether any files were encrypted. RansomHouse is associated with double extortion, in which attackers encrypt systems while threatening to publish stolen data. However, many modern extortion attacks dispense with encryption and rely solely on stolen information as leverage. Active since 2021, RansomHouse is not among the most prolific extortion groups, but it has outlasted many rivals that appeared and disappeared during the same period.

Read full article

This post is licensed under CC BY 4.0 by the author.