Year2023 |
Month |
Reference number20230106 |
Impact areaShore |
Incident locationItaly |
Incident countryItaly |
Victim countryItaly |
Victim identityLiberty Lines |
Victim TypeShipping company |
MethodRansomware |
In September 2023, the LostTrust ransomware group, an evolution of the SFile and Mindware ransomware families, launched a multi-extortion attack on Liberty Lines in Italy. The ransomware, which shares similarities with MetaEncryptor, terminates critical services and processes to facilitate encryption and data exfiltration, removes Volume Shadow Copies, and clears Windows Event Logs. Victims receive ransom notes portraying the attackers as security specialists, threatening to publicize stolen data if the ransom is not paid. The LostTrust leaks site, mirroring the MetaEncryptor site, listed 53 victims at the time of writing. The group, believed to be a rebrand of the MetaEncryptor gang, has targeted various sectors, with the USA and Italy being the most affected. The ransomware appends the “.losttrustencoded” extension to encrypted files and generates ransom notes named “!LostTrustEncoded.txt”. Ransom demands range from $100,000 to several million dollars. SentinelOne's Singularity platform detects and prevents malicious behaviors associated with LostTrust ransomware. The attack on Liberty Lines highlights the ongoing threat posed by ransomware groups and the need for robust cybersecurity measures.