Qilin Ransomware Attack on Better Systems in Thailand

Year

2023

Month

August

Reference number

20230803

Impact area

Shore

Incident location

Thailand

Incident country

Thailand

Victim country

Thailand

Victim identity

Better Systems

Victim Type

Energy company

Method

Ransomware

Summary:

In August 2023, the Qilin ransomware group targeted Thonburi Energy Storage Systems (TESM), a prominent battery manufacturer in Thailand. The group, also known as Agenda, has been active since 2022 and has targeted various sectors including healthcare, education, manufacturing, and real estate. The ransomware operates via a Ransomware-as-a-Service (RaaS) model and uses programming languages like Rust and Go to evade detection. The Rust variant, first observed in December 2022, employs intermittent encryption tactics and uses a double-extortion model, threatening to leak stolen data if the ransom is not paid. The attack on TESM was highlighted by Threat Intelligence Service Falcon Feeds, which shared screenshots from the ransomware group's dark web portal. The Qilin group posted about the attack on August 7, 2023, and provided a link to the targeted website. The ransomware uses Remote Monitoring and Management (RMM) tools and Cobalt Strike for deployment, and employs various techniques for defense evasion, including the use of vulnerable SYS drivers. Organizations are advised to implement security measures such as regular data backups, limited administrative access, and user education to protect against such ransomware attacks.

Reference URL

https://www.trendmicro.com/en_us/research/24/c/agenda-ransomware-propagates-to-vcenters-and-esxi-via-custom-pow.html
https://www.quorumcyber.com/malware-reports/agenda-ransomware-report/
https://thecyberexpress.com/qilin-leaks-data-from-the-tesm-cyber-attack/