Alphv ransomware attack on Slade Shipping in the USA

Year

2023

Month

Reference number

20230109

Impact area

Shore

Incident location

USA

Incident country

USA

Victim country

USA

Victim identity

Slade Shipping

Victim Type

Shipping company

Method

Ransomware

Summary:

In 2023, Slade Shipping in the USA was targeted by the ALPHV ransomware group. The attack began with a malicious email containing a forked IcedID variant, which led to the installation of ScreenConnect for remote control. The attackers used various tools, including Cobalt Strike beacons and CSharp Streamer RAT, to gain credentials and move laterally within the network. Sensitive information was extracted using a custom tool called confucius_cpp. The final payload, ALPHV ransomware, was deployed after deleting backups. A ransom note referencing the group's Twitter was left post-encryption. The consequence of the attack was significant disruption to Slade Shipping's operations and potential data breaches.

Reference URL

https://gbhackers.com/alphv-ransomware-rdp-screenconnect-deployment/