Russian ransomware group reportedly behind Olympus attack

ID theft
(Image credit: Future)

A supposed ongoing ransomware operation against camera giant Olympus is the work of the notorious Russia-based Evil Corp, according to reports.

Based on information from two anonymous sources with knowledge of the incident, TechCrunch says the attack was caused by the Macaw malware, a variant of the WastedLocker malware, both of which are created by Evil Corp.

The ongoing campaign, which began on October 10, and has encrypted Olympus’ systems in the US, Canada and Latin America, follows an earlier BlackMatter-orchestrated attack on the camera giant in September that encrypted its infrastructure across the European, Middle East and Africa regions.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

While Olympus has acknowledged that the October 10 “incident” has caused disruptions, it hasn’t commented on the nature of the attack.

Repeat victims

However, Olympus’ statement inadvertently hints to the fact that it has possibly been attacked by ransomware.

“The nature and scope of the incident is under further investigation and we continue to learn additional details, including the likelihood of data exfiltration,” read the statement. 

Data exfiltration is part of the double-extortion strategy employed by most ransomware operatives, who, in addition to encrypting their victim’s files, also extract a copy of the sensitive ones, which they threaten to release to their competitors. 

Allan Liska, a senior threat analyst at security firm Recorded Future, told TechCrunch that the Macaw malware leaves behind a ransom note on hacked computers that claims to have stolen data from its victims, lending credence to the claims of the anonymous sources.

Unlike Olympus, the Sinclair Broadcast Group, which owns or operates 185 television stations across more than 80 markets, did acknowledge last week that the Macaw malware led to severe disruptions.

Via TechCrunch

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Ransomware
Lee Enterprises blames cyberattack for encrypting critical systems as US newspaper outages drag on
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Ransomware
Atos now says its systems weren't hit by a ransomware attack after all
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
Code Skull
Casio confirms data of 8,500 people exposed in recent ransomware attack
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand