LostTrust Ransomware Attack on Liberty Lines in Italy

Year

2023

Month

Reference number

20230106

Impact area

Shore

Incident location

Italy

Incident country

Italy

Victim country

Italy

Victim identity

Liberty Lines

Victim Type

Shipping company

Method

Ransomware

Summary:

In September 2023, the LostTrust ransomware group, an evolution of the SFile and Mindware ransomware families, launched a multi-extortion attack on Liberty Lines in Italy. The ransomware, which shares similarities with MetaEncryptor, terminates critical services and processes to facilitate encryption and data exfiltration, removes Volume Shadow Copies, and clears Windows Event Logs. Victims receive ransom notes portraying the attackers as security specialists, threatening to publicize stolen data if the ransom is not paid. The LostTrust leaks site, mirroring the MetaEncryptor site, listed 53 victims at the time of writing. The group, believed to be a rebrand of the MetaEncryptor gang, has targeted various sectors, with the USA and Italy being the most affected. The ransomware appends the “.losttrustencoded” extension to encrypted files and generates ransom notes named “!LostTrustEncoded.txt”. Ransom demands range from $100,000 to several million dollars. SentinelOne's Singularity platform detects and prevents malicious behaviors associated with LostTrust ransomware. The attack on Liberty Lines highlights the ongoing threat posed by ransomware groups and the need for robust cybersecurity measures.

Reference URL

https://www.sentinelone.com/blog/losttrust-ransomware-latest-multi-extortion-threat-shares-traits-with-sfile-and-mindware/
https://hackmanac.com/news/losttrust-ransomware-operation-analysis
https://www.cyfirma.com/news/weekly-intelligence-report-06-oct-2023/