Halliburton cyberattack linked to RansomHub ransomware gang
ID: b9dd2917-9716-5d9b-a28d-481c9b2c18bc
STIX ID: report--b9dd2917-9716-5d9b-a28d-481c9b2c18bc
Feed Name: Bleeping Computer
Halliburton disclosed a cyberattack on August 21, 2024 attributed to the RansomHub ransomware gang that disrupted company IT systems and customer transactions; Halliburton took systems offline, engaged Mandiant, notified law enforcement, and provided IOCs to suppliers. Analysis confirmed a RansomHub encryptor (maintenance.exe) with a new -cmd option to run commands pre-encryption, and the report contextualizes RansomHub's activity, links to the defunct Knight operation, and the FBI advisory on the group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
