BlackCat

BlackCat (ALPHV), dubbed the ‘most sophisticated’ ransomware group of 2021, has claimed the responsibility for the Swissport ransomware attack by leaking a small set of sample files that the group claimed to have obtained from Swissport. The threat actor is striving to sell the entire 1.6 TB ‘data dump’ to a prospective buyer.

BlackByte

BlackByte executable leaves a ransom note in all directories where encryption occurs.
RELATED STORIES
Ransomware Found in Critical Infrastructure Sectors
SIM Swapping Attacks Growing: FBI
Embedded Devices Vulnerable to Ransomware Attacks
Russian Cyber Alert Misses Mark For OT
The ransom note includes the .onion site that contains instructions for paying the ransom and receiving a decryption key. Some victims reported the actors used a known Microsoft Exchange Server vulnerability as a means of gaining access to their networks.

Unknown

Unknown cost of attack at this time.

Hacker Attack

Hackers posted messages such as “long delayed because of cyberattack” or “canceled” on the boards. They also urged passengers to call for information, listing the phone number of the office of the country’s supreme leader, Ayatollah Ali Khamenei.