NoEscape Ransomware Attack on RS Logistics in Hong Kong

Year

2023

Month

September

Reference number

20230903

Impact area

Shore

Incident location

Hong Kong

Incident country

Hong Kong

Victim country

Hong Kong

Victim identity

RS Logistics

Victim Type

Logistics company

Method

Ransomware

Summary:

In September 2023, RS Logistics Ltd, a logistics company based in Hong Kong, was targeted by the NoEscape ransomware group. The attackers encrypted the company's data and stole over 4,000 email documents, threatening to publish the data unless contacted by the company. NoEscape, a Ransomware-as-a-Service (RaaS) operation believed to be a rebranding of Avaddon ransomware, emerged in May 2023 and primarily targets industries in the United States while avoiding CIS countries. The ransomware uses a TOR-based platform for multi-extortion, listing victims and hosting exfiltrated data. The attack on RS Logistics, founded in 2003, was reported on September 2, 2023, and the company was listed on NoEscape's data leak site. The ransomware employs various evasion techniques, persistence methods, and disabling security features, with detailed technical analysis provided for detection and defense. The consequence of the attack is the potential exposure of sensitive data and operational disruption for RS Logistics.

Reference URL

https://www.redpacketsecurity.com/noescape-ransomware-victim-rs-logistics-ltd/
https://farghlymal.github.io/NoEscape-Ransomware-Analysis/
https://ransomwareattacks.halcyon.ai/attacks/noescape-attacks-rs-logistics