Hacker mistake reveals ongoing attack on semiconductor company

Cybernews researchers uncovered an active ransomware campaign against multinational semiconductor company V-Silicon after discovering an exposed hacker server.

Here’s a timeline of the findings:

  1. Cybernews researchers discovered an exposed web directory that functioned as a staging server for a ransomware attack.
  2. A subsequent investigation linked the discovered infrastructure to an attack against V-Silicon, a multinational semiconductor company that develops chips used in smart TVs and display devices.
  3. The campaign was attributed to INC Ransomware, a ransomware-as-a-service (RaaS) operation that has been active since 2023.
  4. We alerted V-Silicon to the exposed data on July 17th. 
  5. One day later, the INC ransomware group published V-Silicon on its leak site, claiming responsibility for the attack.

What was found on the internal hacker server?

  • “The artifacts found on the exposed server indicate that during network enumeration, third-party infrastructure and data could have also been compromised”, Cybernews researchers explain.
  • The ransomware was built to run on a wide range of computer systems, suggesting that the attackers may have intended to encrypt embedded controllers, industrial systems, or older semiconductor manufacturing equipment.
  • Researchers noticed coding patterns that suggest some scripts may have been generated with AI.

For more information, here’s the full report: 

https://cybernews.com/security/hackers-exposed-ransomware-attack-v-silicon

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading