El Salvador's Ministry of Local Development Hit by Rhysida Ransomware Attack

Incident Date: Apr 23, 2024

Attack Overview
VICTIM
Ministerio de Desarrollo Local
INDUSTRY
Government
LOCATION
El Salvador
ATTACKER
Rhysida
FIRST REPORTED
April 23, 2024

Ransomware Attack on El Salvador's Ministry of Local Development by Rhysida Group

Overview of the Attack

The Rhysida Ransomware Group, a notorious cybercrime entity, has targeted the Ministerio de Desarrollo Local (MINDEL) of El Salvador. The attack involved the encryption of the ministry's website data, with a ransom demand of 8 BTC (approximately $530,000). The extent of data exfiltration is not fully disclosed, but leaked samples include miscellaneous documents.

Victim Profile: Ministerio de Desarrollo Local

MINDEL, established in 2019, is a decentralized government institution focused on improving the quality of life for those in vulnerable conditions in El Salvador. The ministry is pivotal in planning, controlling, and modernizing aspects related to state procurement. It is headquartered in San Salvador and led by Minister María Ofelia Navarrete de Dubón.

Targeting and Vulnerabilities

The choice of MINDEL as a target by Rhysida can be attributed to several factors:

  • High Impact: As a government entity, MINDEL holds sensitive data and is critical to the administration of local development policies and programs, making it a high-value target.
  • Vulnerabilities in Cybersecurity Measures: Like many government institutions, MINDEL may face challenges in maintaining robust cybersecurity defenses, possibly due to limited resources or rapid digital transformation.
  • Visibility: Attacks on government sites are highly visible and can create significant pressure to pay ransoms, as they affect public services and trust.

Details of the Ransomware Employed

Rhysida ransomware, written in C++, targets Windows operating systems and encrypts files using the ChaCha20 encryption algorithm. The ransom notes are generated as PDF documents named “CriticalBreachDetected.pdf”. The group employs a double extortion technique, threatening to publish stolen data unless the ransom is paid.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.