News: 1623756493

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

The latest REvil ransomware victim? Sol Oriens. Oh, a US nuclear weapons contractor

(2021/06/15)


The REvil ransomware gang, thought to be behind an attack on meat producer JBS which netted an [1]impressive $11m payoff , has found another victim. Worryingly, this one works with the US Department of Defence on the nation's nuclear weapons programme.

According to a statement released by Sol Oriens, the company was hit by "a cybersecurity incident" in May 2021. "The investigation is ongoing," a company spokesperson confirmed, "but we recently determined that an unauthorised individual acquired certain documents from our system. Those documents are currently under review, and we are working with a third-party technological forensic firm to determine the scope of potential data that may have been involved."

Described as a "a small, veteran-owned consulting firm focused on managing advanced technologies and concepts with strong potential for military and space applications," Sol Oriens' links to the US nuclear weapons programme were revealed in a job posting for a "Senior Nuclear Weapons System Subject Matter Expert" on [2]recruitment site Lensa , first spotted by CNBC correspondent [3]Eamon Javers . Those applying were asked to hold a US Department of Defence Top Secret (TS) or the higher Q clearance.

[4]

Thus far, Sol Oriens has not stated - or, less generously, doesn't know - precisely what documents were leaked in the attack, but a spokesperson claimed the company has "no current indication that this incident involves client classified or critical security-related information."

[5]

[6]

A trio of sample documents published to the "Happy Blog," where offers for data captured during REvil-linked ransomware attacks are presented, showed a part of a presentation on recruiting, hiring, and training a contractor workforce at the Los Alamos National Lab marked "Official Use Only" by the US Department of Energy, financial details, and wage reports for five of the company's employees - complete with Social Security numbers.

Sharing proof of the stolen data is akin to sending a pinky in the mail of a kidnap victim

"Sol Oriens, LLC did not take all necessary action to protect personal data of their employees and software developments for partner companies," the perpetrators claimed in the posting. "We hereby keep a right to forward all of the relevant documentation and data to military angencies [sic] of our choise [sic], includig [sic] all personal data of employees."

[7]G7 nations call out Russia for harbouring ransomware crims ahead of Biden-Putin powwow

[8]Ex-NSA leaker Reality Winner released from prison early for 'exemplary' behavior

[9]'I put the interests of the country first': Colonial Pipeline CEO on why oil biz paid off ransomware crooks

[10]The AN0M fake secure chat app may have been too clever for its own good

Public disclosure of the attack came as nations attending the G7 summit [11]called Russia out for allegedly harbouring ransomware gangs, asking the nation to "identify, disrupt, and hold to account those within its borders who conduct ransomware attacks, abuse virtual currency to launder ransoms, and other cybercrimes."

ESET UK cybersecurity expert Jake Moore commented: "Sharing proof of the stolen data is akin to sending a pinky in the mail of a kidnap victim. This extremely powerful group are renowned for getting what they want and with impressive results.

"However, when ransom demands are the favourable choice over a response and recovery plan, it is quite clear we are on a whole new level of disruption knocking over all kinds of organisations. Auctioning off the data proves the severity of the attack as well as highlighting the lack of time as a luxury into deciding what direction Sol Oriens will take in order to dictate their fate." ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2021/06/10/jbs_foods_pays_ransom/

[2] https://lensa.com/senior-nuclear-weapon-system-subject-matter-expert-jobs/albuquerque-nm/hjp/625db000af48ec9d44076c26639e92a4986d2d91a2b45d2887ac1e0851512029

[3] https://twitter.com/EamonJavers/status/1403094483676319745

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMjOn0CZn1CXGKMeV@zv9wAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMjOn0CZn1CXGKMeV@zv9wAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMjOn0CZn1CXGKMeV@zv9wAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/06/14/g7_ransomware_communique_calls_out_russia/

[8] https://www.theregister.com/2021/06/14/reality_winner_released/

[9] https://www.theregister.com/2021/06/09/old_vpn_colonial_pipeline/

[10] https://www.theregister.com/2021/06/14/an0m_and_yamamoto/

[11] https://www.theregister.com/2021/06/14/g7_ransomware_communique_calls_out_russia/

[12] https://whitepapers.theregister.com/

Things that make you go *boom*!

sanmigueelbeer

I think the company should start looking for a new CSO (because the secret is out).

sanmigueelbeer

[1]Nationally-known Australian company lawyered up to resist ASD help

However the unnamed company lawyered up, and it took a week for the ASD to get even basic network information .

" This incident had a national impact on our country. On day 14, we're able to only provide them with generic protection advice, and their network is still down. Three months later, they get reinfected, and we start again ".

This sounds like [2]Toll Group .

[1] https://www.zdnet.com/article/nationally-known-australian-company-lawyered-up-to-resist-asd-help/

[2] https://www.itnews.com.au/news/toll-group-suffers-second-ransomware-attack-this-year-547757

Nothing to see here ...

FuzzyTheBear

it's just normal .. nuclear secrets being kept online so the execs can show off to their friends during dinner parties.

I mean .. keeping nuclear secrets online .. what could possibly go wrong ?

What is the description (copied below) a euphemism for?

CAPS LOCK

"a small, veteran-owned consulting firm focused on managing advanced technologies and concepts with strong potential for military and space applications,"

It's always sad when the fleas leave, because that means your dog is dead.
-- Wesley T. Williams