Suspected Conti Ransomware Activity in the Auto Manufacturing Sector
ID: cdb7e0da-17ee-58b6-9e77-0be3374377e3
STIX ID: report--cdb7e0da-17ee-58b6-9e77-0be3374377e3
Feed Name: Dragos Blog
Executive summary: Dragos observed persistent Emotet C2 communications between multiple Emotet servers and numerous automotive organizations across North America and Japan from December 2021 through March 2022, with telemetry linking a suspected Conti master C2 to Emotet nodes. Affected entities include top automakers and key suppliers; while no confirmed ransomware encryption was observed, the activity indicates established footholds and risk of ransomware impacting IT and OT environments. The report provides a list of C2 IP indicators, analysis of C2 traffic patterns, and recommended detection and mitigation actions (network monitoring, segmentation, patching, backups, and incident response readiness).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
