Full Report
Group-IB experts have detected a massive email campaign spreading similar ransom demands sent to banks and financial organizations across the word.
Analysis Summary
# Incident Report: Global Ransom Email Campaign Against Financial Institutions
## Executive Summary
Group-IB experts identified a massive, coordinated email campaign targeting banks and financial organizations globally with fraudulent ransom demands. The attackers utilized high-volume spam and specialized network attacks, including ICMP flooding and unauthorized port connections, to pressure institutions. While framed as a "ransom" threat, the primary impact observed involved operational disruption and potential reconnaissance via varied network protocols.
## Incident Details
- **Discovery Date:** Not explicitly stated (Report published via Group-IB blog)
- **Incident Date:** Ongoing (referencing campaigns active in 2017 and later)
- **Affected Organization:** Multiple (Undisclosed banks and financial institutions)
- **Sector:** Banking and Financial Services
- **Geography:** Global (APAC, EU, NA, MEA, LATAM)
## Timeline of Events
### Initial Access
- **Date/Time:** 2017 - Ongoing
- **Vector:** Email (Massive Spam Campaign)
- **Details:** Large-scale distribution of emails to financial sector employees containing similar ransom demands, likely designed to cause panic or solicit illicit payments.
### Lateral Movement
- **Movement:** The report indicates external probing rather than deep lateral movement, characterized by connections to various ports (3283, 3702, 389) across diverse international IP addresses.
### Data Exfiltration/Impact
- **Impact:** Service disruption via ICMP flooding and unauthorized network scanning. No confirmed data exfiltration was detailed in this specific report, focusing instead on the extortion and DoS (Denial of Service) aspects.
### Detection & Response
- **Detection:** Identified by Group-IB's Threat Intelligence and Unified Risk Platform through the analysis of global email traffic and network anomalies.
- **Response Actions:** Blocking of known malicious IPs, deployment of Business Email Protection, and engagement of Incident Response teams for targeted organizations.
## Attack Methodology
- **Initial Access:** High-volume malicious email/spam campaigns.
- **Persistence:** Not specified (Focus remained on external pressure and repeated email waves).
- **Defense Evasion:** Use of a wide, geographically diverse infrastructure (over 100+ IPs) to bypass simple IP-based blacklisting.
- **Discovery:** Probing via specialized ports (e.g., Port 389 for LDAP, 3283 for Apple Remote Desktop).
- **Lateral Movement:** Minimal evidence provided; primarily external network attacks.
- **Exfiltration:** N/A (Extortion-focused).
- **Impact:** ICMP flooding (DDoS) and ransom-based psychological pressure.
## Impact Assessment
- **Financial:** Risk of ransom payments; costs associated with incident response and downtime.
- **Data Breach:** None confirmed in the provided text.
- **Operational:** Disruption of network services due to flooding and potential lockdowns during investigation.
- **Reputational:** High risk if the organization is perceived as unable to withstand public extortion attempts.
## Indicators of Compromise
**Network Indicators (Defanged)**
* 179.219.122[.]179:3702
* 128.255.242[.]214:3283
* 91.211.245[.]17:389
* 167.59.10[.]111 (ICMP Flood Source)
* 103.63.190[.]66 (ICMP Flood Source)
* 54.171.57[.]68 (Historical 2017 Campaign IP)
* 77.81.107[.]173 (Historical 2017 Campaign IP)
## Response Actions
- **Containment:** Implementation of network filters to drop ICMP flood traffic and block the identified list of malicious IPs.
- **Eradication:** Scrubbing of email queues to remove ransom messages before delivery to end-users.
- **Recovery:** Restoration of normal network latency following the mitigation of flood attacks.
## Lessons Learned
- **Key Takeaway:** Ransomware groups are increasingly using non-encrypting extortion methods (spam and DDoS) to target the financial sector.
- **Gap:** Traditional email filters may struggle with high-volume, low-malware spam that relies on social engineering (extortion) rather than attachments.
## Recommendations
- **Proactive Monitoring:** Implement Attack Surface Management (ASM) to identify exposed ports (389, 3283) that attackers are actively scanning.
- **Email Security:** Deploy advanced Business Email Protection to identify and quarantine extortion-themed language patterns.
- **DDoS Mitigation:** Ensure robust ICMP rate-limiting and DDoS protection services are active for all public-facing financial infrastructure.