Ranzy Locker Ransomware

Christopher Eaton | October 28th, 2021

 

An October 25, 2021, alert issued by the FBI stated that over 30 US businesses were compromised by threat actors using the Ranzy Locker ransomware. The victims of these attacks are high-value organizations within the critical areas of manufacturing, academia, IT, and transportation. The most recent victims of this ransomware attack were breached through previously known vulnerabilities within their Microsoft Exchange Server and standard phishing scams. The alert further warns of potential future attacks and highlights the importance of remaining vigilant.

Ranzy Locker Ransomware Targeting Companies

The “brute force” Ranzy Locker ransomware attacks employed a double extortion technique: after locating and exfiltrating personally identifiable information (PII) and other high-value data, a demand for ransom (see image) was made in exchange for the decryption code.

Ranzy Locker is yet another example of ransomware-as-a-service, which offers the tools for such attacks to anyone willing to engage and makes identification of the threat actor extremely difficult.

The amorphous risk landscape of such aggressive ransomware attacks demonstrates the need for all organizations to have systems and partners in place to minimize the likelihood of becoming the next victim of Ranzy Locker or other RaaS strikes.

As threat actors and RaaS providers like Ranzy Locker continue to deploy new and sophisticated tactics, knowledge of the current threat landscape and organizational vulnerabilities is increasingly important. At SpearTip, we offer comprehensive pre-breach assessment to identify weaknesses in your systems before the threat actors in addition to our 24/7/365 monitoring of your network, allowing us to respond immediately once a breach occurs. Our certified engineers work in conjunction with our cutting-edge ShadowSpear platform to identify, neutralize, and counter threats before they become devastating and costly ransomware attacks. Our team, who will ensure your organization is not the next victim of Ranzy Locker ransomware, can be reached through email at info@SpearTip.com.

If your company is experiencing a breach, call our Security Operations Centers at 833.997.7327 to speak directly with an engineer.

Categories

Connect With Us

Featured Articles

Cyberattack on UnitedHealth's Change Healthcare
Cyberattack on UnitedHealth's Change Healthcare Results in Multi-Million Dollar Loss
26 April 2024
Industries Vulnerable to Cyberattacks
Industries Vulnerable to Cyberattacks in 2023
24 April 2024
Cybersecurity Health Checks
Cybersecurity Health Checks: Why Companies Need Them
22 April 2024
New Loop DoS Attack
New Loop DoS Attack Affecting Linux Systems
19 April 2024

See ShadowSpear in Action

Identify, neutralize, and counter cyberattacks - provide confidence in your security posture

Stay Connected With SpearTip

Inside the SOC Newsletter

View our articles that cover trending topics in cybersecurity with insights from our 24/7/365 Security Operations Center.

ShadowSpear Platform

Cybersecurity actors are working around the clock, shouldn’t your security team be too? Technology solutions and security controls fail for a number of reasons, poor deployment, improper implementation, or just no one monitoring the alerts.

ShadowSpear Demo

Experience ShadowSpear for yourself. Our lightweight, integrated solution will help you sleep easier at night and provide immediate confidence in your security posture.