Year2023 |
MonthSeptember |
Reference number20230902 |
Impact areaShore |
Incident locationUSA |
Incident countryUSA |
Victim countryUSA |
Victim identityGulf American Line |
Victim TypeFreight forwarding, warehousing, and logistics provider |
MethodRansomware |
In September 2023, Gulf American Lines, a leading freight forwarding, warehousing, and logistics provider headquartered in Berkeley Heights, New Jersey, fell victim to a Medusa Locker ransomware attack. The attackers exploited an external web server, used web shells for access, and employed PowerShell for malicious activities, including disabling antivirus services. They utilized discovery and credential dumping techniques such as Mimikatz and Nishang, and established a reverse tunnel for command and control. Data was exfiltrated and later published on the Medusa leak site, with files encrypted and appended with .MEDUSA. The ransom demand was $100,000. The incident was reported by RedPacket Security, which emphasized its non-affiliation with any ransomware threat actors.