Preston67
12 hours ago
"They don't really target a specific company, they target a specific zero day vulnerability and go after it," Parsons said.
Ransomware attacks involving data theft, known as double extortion, can cause significantly greater damage than conventional encryption-based attacks, as companies risk not only losing control of their information but also having it publicly disclosed.
Shell is one of the world's largest energy companies. A leak of blueprints of its industrial facilities and inspection reports could pose a threat to the physical security of critical infrastructure, as such information could potentially be used to plan acts of sabotage.
Philips is a leading manufacturer of medical equipment. If the reported theft of blueprints and technical schematics is confirmed, the company could suffer significant intellectual property losses due to the risk of design documentation falling into the hands of competitors or malicious parties.
For reference: Cl0p (also known as Clop) is considered one of the most dangerous Russian-speaking cybercriminal groups and has been active since at least early 2019. Cybersecurity researchers have linked its activities to the well-known hacking clusters TA505 and FIN11.
The group operates primarily from Russia and other post-Soviet countries and reportedly follows an unwritten rule of not attacking organisations within the Commonwealth of Independent States (CIS). Cl0p's malware includes checks for keyboard language and operating system settings and automatically stops running if Russian-language settings are detected.
Cl0p was among the pioneers of the "double extortion" tactic, which involves not only blocking access to corporate systems but also threatening to publish confidential data on its dark-web site if victims refuse to pay a ransom in cryptocurrency.
In recent years, the group has largely moved away from conventional encryption of individual networks in favour of mass attacks exploiting zero-day vulnerabilities in widely used corporate software. Notably, the hackers carried out major global campaigns targeting Accellion FTA in 2021, GoAnywhere MFT in early 2023 and MOVEit Transfer in the summer of the same year, compromising data belonging to hundreds of millions of users, major corporations and government agencies in Western countries.