logo

Halliburton cyberattack linked to RansomHub ransomware gang

ID: b9dd2917-9716-5d9b-a28d-481c9b2c18bc

STIX ID: report--b9dd2917-9716-5d9b-a28d-481c9b2c18bc

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-08-29

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Halliburton disclosed a cyberattack on August 21, 2024 attributed to the RansomHub ransomware gang that disrupted company IT systems and customer transactions; Halliburton took systems offline, engaged Mandiant, notified law enforcement, and provided IOCs to suppliers. Analysis confirmed a RansomHub encryptor (maintenance.exe) with a new -cmd option to run commands pre-encryption, and the report contextualizes RansomHub's activity, links to the defunct Knight operation, and the FBI advisory on the group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.