Year2023 |
Month |
Reference number20230109 |
Impact areaShore |
Incident locationUSA |
Incident countryUSA |
Victim countryUSA |
Victim identitySlade Shipping |
Victim TypeShipping company |
MethodRansomware |
In 2023, Slade Shipping in the USA was targeted by the ALPHV ransomware group. The attack began with a malicious email containing a forked IcedID variant, which led to the installation of ScreenConnect for remote control. The attackers used various tools, including Cobalt Strike beacons and CSharp Streamer RAT, to gain credentials and move laterally within the network. Sensitive information was extracted using a custom tool called confucius_cpp. The final payload, ALPHV ransomware, was deployed after deleting backups. A ransom note referencing the group's Twitter was left post-encryption. The consequence of the attack was significant disruption to Slade Shipping's operations and potential data breaches.