RansomHub Ransomware Hits French Municipality Mairie de Mauguio

Incident Date: Oct 22, 2024

Attack Overview
VICTIM
Mairie de Mauguio-Carnon
INDUSTRY
Government
LOCATION
France
ATTACKER
Ransomhub
FIRST REPORTED
October 22, 2024

RansomHub Ransomware Attack on Mairie de Mauguio-Carnon

The Mairie de Mauguio-Carnon, a municipal government in southern France, has fallen victim to a ransomware attack orchestrated by the RansomHub group. This attack has resulted in the exfiltration of 75 GB of sensitive data, with the attackers threatening to release the information if their demands are not met by October 28.

Victim Profile: Mairie de Mauguio-Carnon

The Mairie de Mauguio-Carnon serves as the local government for the commune of Mauguio and its coastal area, Carnon. It plays a vital role in managing community life, including administration, public services, cultural activities, and tourism promotion. The Mairie is notable for its commitment to community engagement and tourism, organizing various cultural and sporting events. As a public institution, it is funded through local taxes and state grants, rather than generating revenue like a private company. The Mairie employs staff across several departments, although specific numbers are not publicly disclosed.

Attack Overview

The ransomware attack has severely disrupted the Mairie's operations, rendering its official website and several online services inaccessible. Municipal services are also unreachable by telephone. The attackers have issued a warning about the critical nature of the files they have obtained, emphasizing the urgency of their ransom demands. The municipality has acknowledged the incident, describing it as a technical issue related to ransomware.

RansomHub: A Formidable Threat

RansomHub, a Ransomware-as-a-Service group, emerged in February 2024 and quickly established itself in the cybercrime landscape. Known for its aggressive affiliate model, RansomHub employs double extortion tactics, encrypting data and exfiltrating sensitive information to increase pressure on victims. The group is affiliated with former Knight ransomware actors and ALPHV/BlackCat, leveraging their expertise to enhance its operations.

Penetration and Distinctive Techniques

RansomHub is renowned for its speed and efficiency, targeting vulnerabilities in systems such as Citrix ADC and FortiOS. The group uses phishing campaigns, vulnerability exploitation, and password spraying to gain initial access. Its ransomware is optimized for cross-platform systems, employing Curve 25519 elliptic curve encryption for security. RansomHub's modular architecture allows affiliates to update strains quickly, avoiding detection and maintaining operational complexity.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.