Hardware giant Gigabyte hit by RansomEXX ransomware forced them to shut down their systems, compromising 112 GB of data...

Continue reading
Gigabyte, a Taiwanese hardware giant, was hit by the RansomEXX ransomware gang that threatened to exposes 112 GB of data unless the company pays a ransom.
Gigabyte is widely known for its high-quality motherboards and other hardware parts such as laptops, graphics cards, data center servers, etc.
According to reports, the attack occurred this Wednesday, which drove the company to shut down its systems based in Taiwan. It also influenced several websites of the company, including its customer support site. After the incident, several customers were unable to access support documents or any uploaded information about RMAs.

United Daily News, a Chinese news website, reported that Gigabyte confirmed the cyberattack that affected a small number of their servers. They shut down their IT systems due to some suspicious activities and immediately notified law enforcement.
The company did not disclose the attackers; security experts believe that the operators behind this ransomware incident were from the RansomEXX group. They identified the attackers through the ransom notes left on the encrypted devices after breaching a network. On the data leak page, the threat actors published screenshots of 4 compromised documents related to NDA.
The data leak page is hosted on a dark web portal used by members of the RansomEXX gang to threaten victim companies and blackmail them for ransom. The page also had a message reading, "We have downloaded 112 GB (120,971,743,713 bytes) of your files, and we are ready to PUBLISH it. Many of them are under NDA (Intel, AMD, American Megatrends). Leak sources: newautobom.gigabyte.intra, git.ami.com.tw, and some others"


Over the past few months, the RasomEXX group has turned out to be more active after the recent attack at Ecuador's state-run Corporación Nacional de Telecomunicación (CNT). while the campaign initially originated under the name of Defray however later rebranded as RansomEXX in 2018. Since then, the threat group has indulged in several adversary campaigns targeting significant tech companies such as Acer , AdvanTech, Compal, Quanta, and Garmin.
RansomEXX doesn't seem to be limited to only targeting the Windows system after the recent reports of Kaspersky confirmed that this group is also natively developed a Linux encryptor that primarily targets to encrypt virtual machines running VMware ESXi servers.

Backdoor.Daxin, the kernel-mode rootkit Symantec once called the most advanced tool ever tied to a China-linked espionage actor, has been found running again