Threat Advisory

RansomEXX claims ransomware attack on Sea-Doo, Ski-Doo maker

Threat: Ransomware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The RansomEXX ransomware gang is claiming responsibility for the cyberattack against Bombardier Recreational Products (BRP), disclosed by the company on August 8, 2022. At the time, the Canadian maker of Ski-Doo snowmobiles, Sea-Doo jet skis, ATVs, motorcycles, watercrafts, and Rotax engines informed the public of a temporary stop for all operations as a response to "malicious cyberactivity." the RansomEXX gang listed Bombardier Recreational Products on its leak site along with 29.9GB of files allegedly stolen from the firm. The samples provided on the onion site include non-disclosure agreements, passports and IDs, material supply agreements, contract renewals, and more. It appears that the data breach doesn't include sensitive customer data, yet the exposure of the said documents is still damaging for BRP. RansomEXX's extortion site lists seven victims in 2022, indicating that the gang's activity is quite low. However, it remains a threat for multiple platforms. Last year, RansomEXX hit some high-profile companies, such as Taiwanese hardware giant GIGABYTE, logistics firm Hellmann Worldwide, Ecuador's state-owned telco CNT, and Italian luxury fashion house Zegna.[/subscribe_to_unlock_form]

Summary:

The RansomEXX ransomware gang is claiming responsibility for the cyberattack against Bombardier Recreational Products (BRP), disclosed by the company on August 8, 2022. At the time, the Canadian maker of Ski-Doo snowmobiles, Sea-Doo jet skis, ATVs, motorcycles, watercrafts, and Rotax engines informed the public of a temporary stop for all operations as a response to "malicious cyberactivity." the RansomEXX gang listed Bombardier Recreational Products on its leak site along with 29.9GB of files allegedly stolen from the firm. The samples provided on the onion site include non-disclosure agreements, passports and IDs, material supply agreements, contract renewals, and more. It appears that the data breach doesn't include sensitive customer data, yet the exposure of the said documents is still damaging for BRP. RansomEXX's extortion site lists seven victims in 2022, indicating that the gang's activity is quite low. However, it remains a threat for multiple platforms. Last year, RansomEXX hit some high-profile companies, such as Taiwanese hardware giant GIGABYTE, logistics firm Hellmann Worldwide, Ecuador's state-owned telco CNT, and Italian luxury fashion house Zegna.[emaillocker id="1283"]

                                                                  Figure : RansomEXX infection chain   

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/ransomexx-claims-ransomware-attack-on-sea-doo-ski-doo-maker/

https://documents.trendmicro.com/images/TEx/ioc_ransomexx_spotlight2PznnpU.txt

[/emaillocker]
crossmenu