REvil hacking group attacks US nuclear weapons contractor

There’s no indication the stolen data includes classified or critical security-related information

Ransomware warning on a compute screen with a URL address bar above it

The same gang behind the REvil ransomware-as-a-service operation has attacked US nuclear weapons contractor Sol Oriens. The criminals claimed they would auction the data stolen during the attack.

The REvil ransomware cyber crime gang recently listed organizations whose data it was selling to the highest bidder — one of those companies was Sol Oriens. To prove they had the data, the hackers posted images of a hiring overview document and other corporate documents.

After the hackers published the images, Sols Oriens confirmed an attack occurred in May 2021. CNBC reporter Eamon Javers shared the confirmation on Twitter.

“The investigation is ongoing, but we recently determined that an unauthorized individual acquired certain documents from our systems,” the statement read. “Those documents are currently under review, and we are working with a third-party technological forensic firm to determine the scope of potential data that may have been involved.”

“We have no current indication that this incident involves client classified or critical security-related information. Once the investigation concludes, we are committed to notifying individuals and entities whose information is involved.”

Martin Jartelius, CSO at Outpost24, told ITPro the REvil gang depends largely on subcontractors making the initial breaches. After the initial breach, the REvil gang executes the ransom component.

“While the target is highly interesting, we hence should note that Russian interests have access to this capability and the implications this carries for the supply-chain – in this case, we saw ransomware but that was the option chosen by the attacker once they had access,” said Jartelius. “Ransomware is the symptom, not the cause of ailment. We hope that the breach in and of itself does not cause unnecessary instability on a larger scale, on the positive side different threat actors have recently kicked so many hornets' nests in a short period of time, soon one or more are bound to be stung."

Paul Norris, senior systems engineer EMEA at Tripwire, told ITPro that groups like REvil have been wildly successful at monetizing data exfiltrated from their victims. 

“We should hope that Sol Oriens is prepared to respond to ransomware, including the potential operational disruptions that come with that response. But while we tend to focus on the response to ransomware, prevention is still the best way to deal with the threat,” said Norris. “Ransomware doesn’t magically appear on systems, and the methods by which it’s introduced into an environment are generally well-understood phishing, vulnerability exploits, and misconfigurations, which is why hardening systems helps to safeguard the integrity of your digital assets and protect against vulnerabilities."

Featured Resources

How virtual desktop infrastructure enables digital transformation

Challenges and benefits of VDI

Free download

The Okta digital trust index

Exploring the human edge of trust

Free download

Optimising workload placement in your hybrid cloud

Deliver increased IT agility with the cloud

Free Download

Modernise endpoint protection and leave your legacy challenges behind

The risk of keeping your legacy endpoint security tools

Download now

Recommended

Russia's "politically motivated" REvil raid could be used as leverage, experts warn
ransomware

Russia's "politically motivated" REvil raid could be used as leverage, experts warn

17 Jan 2022
Meta files lawsuit to uncover hackers targeting Facebook, WhatsApp
phishing

Meta files lawsuit to uncover hackers targeting Facebook, WhatsApp

21 Dec 2021
Five things to consider before choosing an MFA solution
Security

Five things to consider before choosing an MFA solution

17 Dec 2021
Australia and US sign CLOUD Act data-sharing deal to support criminal investigations
cyber crime

Australia and US sign CLOUD Act data-sharing deal to support criminal investigations

16 Dec 2021

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

6 Jan 2022
Sony pulls out of MWC 2022
Business operations

Sony pulls out of MWC 2022

14 Jan 2022
Dell XPS 15 (2021) review: The best just got better
Laptops

Dell XPS 15 (2021) review: The best just got better

14 Jan 2022