Year2018 |
MonthSeptember |
Reference number20180901 |
Impact areaShore |
Incident locationBarcelona |
Incident countrySpain |
Victim countrySpain |
Victim identityPort of Barcelona |
Victim TypePort |
MethodRansomware |
On September 20, the port of Barcelona got hit by a Ryuk ransomware attack. The attackers use manual hacking techniques and open-source tools to move laterally through private networks and gain administrative access to as many systems as possible before initiating the file encryption. Once deployed, Ryuk encrypts all files except for those with the extensions dll, lnk, hrmlog, ini and exe. It also skips files stored in the Windows System32, Chrome, Mozilla, Internet Explorer and Recycle Bin directories. Ryuk uses strong file encryption based on AES-256. The attack only affected internal IT Systems, and did not affect any shipping movements in and out of the harbour.