← Haldiram Foods

2020 — In what looks to be an unusual choice of victim, a…

2020 Unknown records affected Share on X

Data compromised

Internal

Technical writeup

In what looks to be an unusual choice of victim, a cyber criminal gang has used the Maze Windows ransomware to attack the well-known Indian sweets manufacturer Haldiram's and has released some data stolen from the company. Ransomware packages are designed to encrypt files found on a victim's site. The exfiltration of files is done through PowerShell scripts. The release of the zipped data is an indication that the victim has not yet responded to the ransom note generated by the ransomware after the encryption process is complete. The file put online appears to be corrupt and the contents cannot be viewed.

Root cause

Malware: Ransomware

References