Year2023 |
MonthAugust |
Reference number20230803 |
Impact areaShore |
Incident locationThailand |
Incident countryThailand |
Victim countryThailand |
Victim identityBetter Systems |
Victim TypeEnergy company |
MethodRansomware |
In August 2023, the Qilin ransomware group targeted Thonburi Energy Storage Systems (TESM), a prominent battery manufacturer in Thailand. The group, also known as Agenda, has been active since 2022 and has targeted various sectors including healthcare, education, manufacturing, and real estate. The ransomware operates via a Ransomware-as-a-Service (RaaS) model and uses programming languages like Rust and Go to evade detection. The Rust variant, first observed in December 2022, employs intermittent encryption tactics and uses a double-extortion model, threatening to leak stolen data if the ransom is not paid. The attack on TESM was highlighted by Threat Intelligence Service Falcon Feeds, which shared screenshots from the ransomware group's dark web portal. The Qilin group posted about the attack on August 7, 2023, and provided a link to the targeted website. The ransomware uses Remote Monitoring and Management (RMM) tools and Cobalt Strike for deployment, and employs various techniques for defense evasion, including the use of vulnerable SYS drivers. Organizations are advised to implement security measures such as regular data backups, limited administrative access, and user education to protect against such ransomware attacks.