{"id":37400,"date":"2022-06-29T06:23:00","date_gmt":"2022-06-29T06:23:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/37400"},"modified":"2022-06-29T06:23:00","modified_gmt":"2022-06-29T06:23:00","slug":"new-cyber-extortion-op-appears-to-have-hit-amd","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=37400","title":{"rendered":"New cyber extortion op appears to have hit AMD"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/06\/new-cyber-extortion-op-appears-to-have-hit-amd.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>A relatively new data extortion operation going by the name RansomHouse appears to have turned over the systems of semiconductor specialist AMD, stealing more than 450GB of the organisation\u2019s data and holding it to ransom.<\/p>\n<p>As initially reported by <em><a href=\"https:\/\/restoreprivacy.com\/ransomhouse-group-amd-advanced-micro-devices\/\">Restore Privacy<\/a><\/em>, which said it was tipped off by the gang itself, AMD\u2019s systems were first compromised in January 2022. Samples of AMD\u2019s data have now appeared on the group\u2019s dark website, and <em>Restore Privacy<\/em> has verified that the data seems to be authentic.<\/p>\n<p>The report went on to quote RansomHouse\u2019s operative as claiming that those responsible for network protection at AMD had been using the password \u201cpassword\u201d. This may be an indication of a successful credential stuffing attack.<\/p>\n<p>Successfully contacted by <em><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/amd-investigates-ransomhouse-hack-claims-theft-of-450gb-data\/\">Bleeping Computer<\/a><\/em>, the gang, which makes a point of stating it is not a traditional ransomware operation, said it had not contacted AMD to demand money, as it would be more worth its while to sell the stolen data to other threat actors.<\/p>\n<p>In response to the report, AMD said it was aware of a malicious actor claiming to be in possession of its data and that it had started an investigation.<\/p>\n<p>As always in such situations, there is a lack of clarity over the precise nature of the situation, including factors such as how the data was obtained and when \u2013 although there has been <a href=\"https:\/\/twitter.com\/campuscodi\/status\/1541537953691975682\">a persistent rumour<\/a> that AMD was hit by ransomware earlier this year.<\/p>\n<p>It would be unwise to take RansomHouse at its word, as cyber criminal operations are known to make false claims when courting publicity.<\/p>\n<div id>\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Who is RansomHouse?<\/h3>\n<p>A new player in the fast-evolving cyber criminal underground, RansomHouse emerged late in 2021 and, to date, its dark web leak site has listed a total of six victims. Its first victim, in December 2021, was Canada\u2019s Saskatchewan Liquor and Gaming Authority (SLGA). More recently, it leaked data stolen from South Africa-based retailer ShopRite, which is Africa\u2019s largest private sector employer.<\/p>\n<p>According to intelligence published in May 2022 by <a href=\"https:\/\/cyberint.com\/\">Cyberint<\/a>, the gang is notable for not cleaving to the traditional model of a data extortion operation, claiming to be motivated by more than just financial gain and depicting its victims as the real villains for not taking security seriously.<\/p>\n<p><a href=\"https:\/\/cyberint.com\/blog\/research\/ransomhouse\/\">Cyberint said<\/a> it had confirmed that RansomHouse\u2019s campaigns were focused on extortion only, and that it did not possess or develop any encryption module.<\/p>\n<p>Jim Simpson, director of threat intelligence at <a href=\"https:\/\/www.slcyber.io\/\">Searchlight Security<\/a>, said RansomHouse seemed to be taking to an extreme the archetype of an \u201cethical\u201d data extortion gang, the sort of malicious actors who claim their motivation is simply to improve the information security standards of their victims, albeit by conducting unscheduled penetration tests.<\/p>\n<blockquote class=\"main-article-pullquote\">\n<p><figure> \u201cWhile RansomHouse\u2019s attitude might be unusual, their methods and motivations are as common and mercenary as any other criminal\u2019s\u201d <\/figure><figcaption> <strong>Jonathan Knudsen, Synopsys Cybersecurity Research Center<\/strong> <\/figcaption><i class=\"icon\" data-icon=\"z\"><\/i> <\/p>\n<\/blockquote>\n<p>\u201cRansomHouse claims its primary goal is to \u2018minimise the damage that might be sustained by related parties and raising awareness of data security and privacy issues,\u201d said Simpson.<\/p>\n<p>\u201cHowever, their stated frustration with \u2018ridiculously small\u2019 bug bounty amounts paid out by companies and the whole operation \u2013 holding data hostage until a victim pays the ransom, or selling it to other threat actors in the event they refuse \u2013 makes it clear they are a financially motivated threat and want money from their victims,\u201d he added.<\/p>\n<p>\u201cIf the victims refuse to pay the requested ransom, and no one decides to buy it, RansomHouse will publicly share the stolen data on their dark web PR site and Telegram channel,\u201d continued Simpson.<\/p>\n<p>\u201cIn another attempt to create a veneer of benevolence, the group claims that individuals who fear they are part of a soon-to-be-leaked dataset can request via Telegram to have their information removed before publication \u2013 however, our assessment is it is unlikely to be true.\u201d<\/p>\n<p>Jonathan Knudsen, head of global research at the <a href=\"https:\/\/www.synopsys.com\/software-integrity\/cybersecurity-research-center.html\">Synopsys Cybersecurity Research Center<\/a>, added: \u201cCyber security adversaries come in all shapes and sizes, with all kinds of motivations. Recently, RansomHouse has been engaging with a cyber twist on victim shaming. They claim that \u2018the culprits are those who did not put a lock on the door leaving it wide open inviting everyone in\u2019.<\/p>\n<p>\u201c[But] organisations who have poor cyber security do not deserve to be victims. If you were walking past a house and saw the door open, what would you do? You would not enter the house uninvited, and you would not steal a TV or jewellery just to prove that the house owner was not following good security practices.<\/p>\n<p>\u201cWhile RansomHouse\u2019s attitude might be unusual, their methods and motivations are as common and mercenary as any other criminal\u2019s,\u201d noted Knudsen.<\/p>\n<p><strong>&nbsp;<\/strong><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A relatively new data extortion operation going by the name RansomHouse appears to have turned over the systems of semiconductor specialist AMD, stealing more than 450GB of the organisation\u2019s data and holding it to ransom. As initially reported by Restore Privacy, which said it was tipped off by the gang itself, AMD\u2019s systems were first [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":37401,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-37400","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/37400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=37400"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/37400\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/37401"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=37400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=37400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=37400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}