Digital Times Nigeria
  • Home
  • Telecoms
    • Broadband
  • Business
    • Banking
    • Finance
  • Editorial
    • Opinion
    • Big Story
  • TechExtra
    • Fintech
    • Innovation
  • Interview
  • Media
    • Social
    • Broadcasting
Facebook X (Twitter) Instagram
Trending
  • Trump Demands Intel CEO Lip-Bu Tan Resign Over China Ties
  • NCC Sounds Alarm On Telecom Vandalism, Pushes For Nationwide Collaboration To Safeguard Telecom Infrastructure
  • Google’s Gemini Now Turns Your Ideas And Images Into Nigerian Storybooks
  • Meta, I.N OFFICIAL Partner To Launch First AI-Powered Fashion Collection At Africa Fashion Week London
  • Telecom Operators Raise Alarm Over Diesel Blockade Threatening Nationwide Connectivity
  • Zinox Shares Innovation Story On Konga 103.7FM
  • Hippo 2027: Obowo’s Lion Roars For The Assembly Seat
  • NITDA Pushes Gender Inclusion With IgniteHer, Fuels Tinubu’s Renewed Hope Vision
Facebook X (Twitter) Instagram
Digital Times NigeriaDigital Times Nigeria
  • Home
  • Telecoms
    • Broadband
  • Business
    • Banking
    • Finance
  • Editorial
    • Opinion
    • Big Story
  • TechExtra
    • Fintech
    • Innovation
  • Interview
  • Media
    • Social
    • Broadcasting
Digital Times Nigeria
Home » Sophos Research Details How Conti Gang, Karma Dual Ransomware Attack Hold Business Hostage
Business

Sophos Research Details How Conti Gang, Karma Dual Ransomware Attack Hold Business Hostage

Our REPORTERBy Our REPORTER10 March 2022No Comments4 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
CONTI
Share
Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp

Sophos, a global leader in next-generation cybersecurity, has released findings of a dual ransomware attack where extortion notes left by Karma ransomware operators were encrypted 24 hours later by Conti, another ransomware gang that was on the target’s network at the same time.

In the article, Sophos details the dual attacks, “Conti and Karma Actors Attack Healthcare Provider at Same Time Through ProxyShell Exploits,” explaining how both operators gained access to the network through an unpatched Microsoft Exchange Server, but then used different tactics to implement their attacks.

“To be hit by a dual ransomware attack is a nightmare scenario for any organization. Across the estimated timeline, there was a period of around four days when the Conti and Karma attackers were simultaneously active in the target’s network, moving around each other, downloading and running scripts, installing Cobalt Strike beacons, collecting and exfiltrating data, and more,” said Sean Gallagher, senior threat researcher, Sophos.

“Karma deployed the final stage of its attack first, dropping an extortion notice on computers demanding a bitcoin payment in exchange for not publishing stolen data. Then Conti struck, encrypting the target’s data in a more traditional ransomware attack.

CYBER1
A man holds a laptop computer as cyber code is projected on him in this illustration picture taken on May 13, 2017. REUTERS/Kacper Pempel/Illustration

In a strange twist, the Conti ransomware encrypted Karma’s extortion notes.

“We have seen several cases recently where ransomware affiliates, including affiliates of Conti, used ProxyShell exploits to penetrate targets’ networks. We have also seen examples of multiple actors exploiting the same vulnerability to gain access to a victim.

“However, very few of those cases involved two ransomware groups simultaneously attacking a target and it shows, literally, how crowded and competitive the ransomware landscape has become.”

READ ALSO  54gene Wins World Economic Forum ‘Technology Pioneer’ Award

The Dual Attack

Sophos believes that the first incident started on Aug. 10, 2021, when attackers, possibly Initial Access Brokers, used a ProxyShell exploit to gain access to the network and establish a foothold on the compromised server.

The Sophos investigation showed that almost four months passed before Karma appeared on Nov. 30, 2021, and exfiltrated more than 52 gigabytes of data to the cloud.

On Dec. 3, 2021, three things happened:

  • The Karma attackers dropped an extortion note on 20 computers, demanding a ransom and explaining that they did not encrypt the data because the target was a healthcare provider
  • Conti was quietly operating in the background also exfiltrating data
  • The target started onboarding Sophos’ incident response team to help with Karma

While Sophos was onboarding, Conti deployed its ransomware on Dec. 4, 2021. It subsequently tracked the start of the Conti attack to another ProxyShell exploits leveraged on Nov. 25, 2021.CONTI 3 1

CONTI 4“Whether the initial access broker-sold access to two different ransomware affiliates, or whether the vulnerable Exchange server was just an unlucky target for multiple ransomware operators, the fact that a dual attack was possible is a powerful reminder to patch widely known, internet-facing vulnerabilities at the earliest opportunity,” said Gallagher.

“Defense-in-depth is vital for identifying and blocking attackers at any stage of the attack chain, while proactive, human-led threat hunting should investigate all potentially suspicious behaviour, such as unexpected remote access service logins or the use of legitimate tools outside the normal pattern, as these could be early warning signs of an imminent ransomware attack.”

READ ALSO  NCC Fully Ready For 5G Deployment In Nigeria- Danbatta

Sophos endpoint products, such as Intercept X, protect users by detecting the actions and behaviours of ransomware and other attacks, such as those described in this Sophos research.

For further information read the article, “Conti and Karma Actors Attack Healthcare Provider at Same Time Through ProxyShell Exploits.”

Sophos is a worldwide leader in next-generation cybersecurity, protecting more than 500,000 organizations and millions of consumers in more than 150 countries from today’s most advanced cyberthreats.

Powered by threat intelligence, AI and machine learning from SophosLabs and SophosAI, Sophos delivers a broad portfolio of advanced products and services to secure users, networks and endpoints against ransomware, malware, exploits, phishing and the wide range of other cyberattacks.

Sophos provides a single integrated cloud-based management console, Sophos Central – the centrepiece of an adaptive cybersecurity ecosystem that features a centralized data lake that leverages a rich set of open APIs available to customers, partners, developers, and other cybersecurity vendors.

#Conti Gang #Dual Ransomware Attack #Hostage #Karma #Sophos #Sophos Research business Featured
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDriving Product Adoption: Strategies For Effective Product Launches
Next Article Phase3 Telecom Moves Onto Digital Connectivity Enterprise In Nigeria And West African Sub-Region
Our REPORTER
  • Website

Related Posts

Meta, I.N OFFICIAL Partner To Launch First AI-Powered Fashion Collection At Africa Fashion Week London

8 August 2025

Konga Flags Off Back-To-School Campaign

6 August 2025

Style, Sound, And Culture Meet As LG Unveils ‘xboom by will.i.am’ In Nigeria

6 August 2025

7 Steps For Checking Your 2025 WASSCE Results

4 August 2025

WAEC Releases 2025 WASSCE Results, Records Sharp Drop In Performance Amid New Anti-Cheating Measures

4 August 2025

Telecom Stakeholders Converge On Lagos For Maiden CNII & Telecom Sustainability Conference

4 August 2025

Comments are closed.

Categories
About
About

Digital Times Nigeria (www.digitaltimesng.com) is an online technology publication of Digital Times Media Services.

Facebook X (Twitter) Instagram
Latest Posts

Trump Demands Intel CEO Lip-Bu Tan Resign Over China Ties

8 August 2025

NCC Sounds Alarm On Telecom Vandalism, Pushes For Nationwide Collaboration To Safeguard Telecom Infrastructure

8 August 2025

Google’s Gemini Now Turns Your Ideas And Images Into Nigerian Storybooks

8 August 2025
Popular Posts

Building Explainable AI (XAI) Dashboards For Non-Technical Stakeholders

2 May 2022

Building Ethical AI Starts With People: How Gabriel Ayodele Is Engineering Trust Through Mentorship

8 January 2024

Gabriel Tosin Ayodele: Leading AI-Powered Innovation In Web3

8 November 2022
© 2025 Digital Times NG. Designed by Max Excellence LLC.
  • Advert Rate
  • Terms of Use
  • Advertisement
  • Private Policy
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.