HPE-ILO-4-RANSOMWARE

HPE-ILO-4-RANSOMWAREHPE iLO 4 Ransomware

Description

Attackers are targeting Internet accessible HPE iLO 4 remote management interfaces, supposedly encrypting the hard drives, and then demanding Bitcoins to get access to the data again. According to the victim, the attackers are demanding 2 bitcoins to gain access to the drives again. The attackers will also provide a bitcoin address to the victim that should be used for payment. These bitcoin addresses appear to be unique per victim as the victim's was different from other reported ones. An interesting part of the ransom note is that the attackers state that the ransom price is not negotiable unless the victim's are from Russia. This is common for Russian based attackers, who in many cases tries to avoid infecting Russian victims. Finally, could this be a decoy/wiper rather than an actual true ransomware attack? Ransomware attacks typically provide a unique ID to the victim in order to distinguish one victim from another. This prevents a victim from "stealing" another victim's payment and using it to unlock their computer. In a situation like this, where no unique ID is given to identify the encrypted computer and the email is publicly accessible, it could be a case where the main goal is to wipe a server or act as a decoy for another attack.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
HCrypto
Software
HDLocker
Software
Pay2Decrypt
Software
Russian EDA2
Software
IT.Books
Software
HackedLocker Ransomware
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.