Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
Cybersecurity experts reveal what exactly happened in the ransomware attacks that took down 300 banks
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • Cybersecurity experts reveal what exactly happened in the ransomware attacks that took down 300 banks

Cybersecurity experts reveal what exactly happened in the ransomware attacks that took down 300 banks

FP Staff • August 1, 2024, 16:38:58 IST
Whatsapp Facebook Twitter

Very basically, C-Edge Technologies Ltd, the joint venture between Tata Consultancy Services Ltd and State Bank of India was attacked using a sophisticated variant of their ransomware according to a report by CloudSEK

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Cybersecurity experts reveal what exactly happened in the ransomware attacks that took down 300 banks

The recent ransomware attack that basically took down over 300 small Indian banks and has rendered ATM usage and online payments has been attributed to the notorious RansomEXX group

What happened was that C-Edge Technologies Ltd., a joint venture between Tata Consultancy Services Ltd. and State Bank of India was attacked using a sophisticated variant of their ransomware according to a report by CloudSEK

The attack primarily affected Brontoo Technology Solutions, a significant collaborator with C-Edge. Following the attack, Brontoo filed a report with CertIn, the Indian Computer Emergency Response Team. CloudSEK’s threat research team identified that the attack chain began with a misconfigured Jenkins server, which the attackers exploited.

STORY CONTINUES BELOW THIS AD

Key Findings from the CloudSEK Report
CloudSEK’s report highlighted several key findings. The ransomware group behind the attack is RansomEXX v2.0, which is notorious for targeting large organizations and demanding substantial ransom payments. The attack began with a misconfigured Jenkins server, exploiting a vulnerability (CVE-2024-23897) that allows attackers to gain secure shell access via port 22. This incident underscores the growing threat of supply chain attacks and the need for robust security measures across entire ecosystems.

More from Tech
How ChatGPT is becoming everyone’s BFF and why that’s dangerous How ChatGPT is becoming everyone’s BFF and why that’s dangerous America ready for self-driving cars, but it has a legal problem America ready for self-driving cars, but it has a legal problem

RansomEXX v2.0 is an advanced variant of the RansomEXX ransomware, known for its sophisticated techniques and high ransom demands. Initially known as Defray777, RansomEXX rebranded in 2020 and has since evolved to counter increasing defensive measures. This variant shows enhanced encryption techniques, evasion tactics, and payload delivery methods.

The infection vectors and tactics used by RansomEXX v2.0 are diverse and effective. The initial access vectors include phishing emails, exploiting vulnerabilities in remote desktop protocols (RDP), and weaknesses in VPNs and other remote access services. After gaining initial access, the group uses tools like Cobalt Strike and Mimikatz to move laterally within a network. They employ known exploits and credential theft to gain higher privileges within the compromised environment.

Rise of the Superbug
RansomEXX v2.0 employs strong encryption algorithms such as RSA-2048 and AES-256, making file recovery without the decryption key virtually impossible. The ransomware targets critical files and backups, rendering them inaccessible. Before encryption, the group often exfiltrates data to use as leverage for double extortion. Victims receive detailed ransom notes with instructions for payment, typically in Bitcoin or other cryptocurrencies. The group is known to engage in negotiations, sometimes lowering ransom demands based on the victim’s response and perceived ability to pay.

Impact Shorts

More Shorts
America ready for self-driving cars, but it has a legal problem

America ready for self-driving cars, but it has a legal problem

Alibaba, Baidu begin using own AI chips as China shifts away from US tech amid Nvidia row

Alibaba, Baidu begin using own AI chips as China shifts away from US tech amid Nvidia row

RansomEXX has targeted a range of high-profile organizations across various sectors, including government agencies, healthcare providers, and multinational corporations. These attacks have resulted in significant operational disruptions, data breaches, and financial losses. Many victims have paid the ransom to quickly restore operations.

RansomEXX v2.0 continues to evolve, incorporating new techniques to bypass security measures. Recent reports indicate the use of stolen digital certificates to sign malware, increasing trust and reducing detection rates, says CloudSEK. There is also evidence of collaboration with other cybercriminal groups, sharing tools, techniques, and infrastructure.

STORY CONTINUES BELOW THIS AD
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

America ready for self-driving cars, but it has a legal problem

America ready for self-driving cars, but it has a legal problem

US self-driving cars may soon ditch windshield wipers as the NHTSA plans to update regulations by 2026. State-level rules vary, complicating nationwide deployment. Liability and insurance models are also evolving with the technology.

More Impact Shorts

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV