Digital Times Nigeria
  • Home
  • Telecoms
    • Broadband
  • Business
    • Banking
    • Finance
  • Editorial
    • Opinion
    • Big Story
  • TechExtra
    • Fintech
    • Innovation
  • Interview
  • Media
    • Social
    • Broadcasting
Facebook X (Twitter) Instagram
Trending
  • BREAKING: Okonjo-Iweala Honoured With ACFE’s Highest Anti-Fraud Award
  • Nominations Open As CIO & C-Suite Awards Africa 2025 Expands Across 15 African Countries
  • IHS Nigeria, UNICEF Assess Lifesaving Impact Of Installed Oxygen Plant In Oyo State
  • Africa Gears Up For Digital Sovereignty At 13th Digital Africa Conference 2025
  • How Leo Stan Ekeh Founded Zinox Group To Power Nigeria’s Digital Confidence
  • Femi Soneye Steps Down As NNPCL Spokesperson
  • Nnaemeka Ani Urges African Tech Innovators To Build With Legacy In Mind
  • Empowering The Displaced: NITDA, NCFRMI Strengthen Alliance For Digital Inclusion
Facebook X (Twitter) Instagram
Digital Times NigeriaDigital Times Nigeria
  • Home
  • Telecoms
    • Broadband
  • Business
    • Banking
    • Finance
  • Editorial
    • Opinion
    • Big Story
  • TechExtra
    • Fintech
    • Innovation
  • Interview
  • Media
    • Social
    • Broadcasting
Digital Times Nigeria
Home » Sophos Research Details How Conti Gang, Karma Dual Ransomware Attack Hold Business Hostage
Business

Sophos Research Details How Conti Gang, Karma Dual Ransomware Attack Hold Business Hostage

Our REPORTERBy Our REPORTER10 March 2022No Comments4 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
CONTI
Share
Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp

Sophos, a global leader in next-generation cybersecurity, has released findings of a dual ransomware attack where extortion notes left by Karma ransomware operators were encrypted 24 hours later by Conti, another ransomware gang that was on the target’s network at the same time.

In the article, Sophos details the dual attacks, “Conti and Karma Actors Attack Healthcare Provider at Same Time Through ProxyShell Exploits,” explaining how both operators gained access to the network through an unpatched Microsoft Exchange Server, but then used different tactics to implement their attacks.

“To be hit by a dual ransomware attack is a nightmare scenario for any organization. Across the estimated timeline, there was a period of around four days when the Conti and Karma attackers were simultaneously active in the target’s network, moving around each other, downloading and running scripts, installing Cobalt Strike beacons, collecting and exfiltrating data, and more,” said Sean Gallagher, senior threat researcher, Sophos.

“Karma deployed the final stage of its attack first, dropping an extortion notice on computers demanding a bitcoin payment in exchange for not publishing stolen data. Then Conti struck, encrypting the target’s data in a more traditional ransomware attack.

CYBER1
A man holds a laptop computer as cyber code is projected on him in this illustration picture taken on May 13, 2017. REUTERS/Kacper Pempel/Illustration

In a strange twist, the Conti ransomware encrypted Karma’s extortion notes.

“We have seen several cases recently where ransomware affiliates, including affiliates of Conti, used ProxyShell exploits to penetrate targets’ networks. We have also seen examples of multiple actors exploiting the same vulnerability to gain access to a victim.

“However, very few of those cases involved two ransomware groups simultaneously attacking a target and it shows, literally, how crowded and competitive the ransomware landscape has become.”

READ ALSO  Choosing The Right Mix Of Tools For Your Business To Sidestep Silos

The Dual Attack

Sophos believes that the first incident started on Aug. 10, 2021, when attackers, possibly Initial Access Brokers, used a ProxyShell exploit to gain access to the network and establish a foothold on the compromised server.

The Sophos investigation showed that almost four months passed before Karma appeared on Nov. 30, 2021, and exfiltrated more than 52 gigabytes of data to the cloud.

On Dec. 3, 2021, three things happened:

  • The Karma attackers dropped an extortion note on 20 computers, demanding a ransom and explaining that they did not encrypt the data because the target was a healthcare provider
  • Conti was quietly operating in the background also exfiltrating data
  • The target started onboarding Sophos’ incident response team to help with Karma

While Sophos was onboarding, Conti deployed its ransomware on Dec. 4, 2021. It subsequently tracked the start of the Conti attack to another ProxyShell exploits leveraged on Nov. 25, 2021.CONTI 3 1

CONTI 4“Whether the initial access broker-sold access to two different ransomware affiliates, or whether the vulnerable Exchange server was just an unlucky target for multiple ransomware operators, the fact that a dual attack was possible is a powerful reminder to patch widely known, internet-facing vulnerabilities at the earliest opportunity,” said Gallagher.

“Defense-in-depth is vital for identifying and blocking attackers at any stage of the attack chain, while proactive, human-led threat hunting should investigate all potentially suspicious behaviour, such as unexpected remote access service logins or the use of legitimate tools outside the normal pattern, as these could be early warning signs of an imminent ransomware attack.”

READ ALSO  At Cool-C Car Mart, Quality Cars And Affordable Prices Stand Us Out- Izuh

Sophos endpoint products, such as Intercept X, protect users by detecting the actions and behaviours of ransomware and other attacks, such as those described in this Sophos research.

For further information read the article, “Conti and Karma Actors Attack Healthcare Provider at Same Time Through ProxyShell Exploits.”

Sophos is a worldwide leader in next-generation cybersecurity, protecting more than 500,000 organizations and millions of consumers in more than 150 countries from today’s most advanced cyberthreats.

Powered by threat intelligence, AI and machine learning from SophosLabs and SophosAI, Sophos delivers a broad portfolio of advanced products and services to secure users, networks and endpoints against ransomware, malware, exploits, phishing and the wide range of other cyberattacks.

Sophos provides a single integrated cloud-based management console, Sophos Central – the centrepiece of an adaptive cybersecurity ecosystem that features a centralized data lake that leverages a rich set of open APIs available to customers, partners, developers, and other cybersecurity vendors.

#Conti Gang #Dual Ransomware Attack #Hostage #Karma #Sophos #Sophos Research business Featured
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDriving Product Adoption: Strategies For Effective Product Launches
Next Article Phase3 Telecom Moves Onto Digital Connectivity Enterprise In Nigeria And West African Sub-Region
Our REPORTER
  • Website

Related Posts

Nominations Open As CIO & C-Suite Awards Africa 2025 Expands Across 15 African Countries

24 June 2025

Africa Gears Up For Digital Sovereignty At 13th Digital Africa Conference 2025

24 June 2025

How Leo Stan Ekeh Founded Zinox Group To Power Nigeria’s Digital Confidence

23 June 2025

Empowering The Displaced: NITDA, NCFRMI Strengthen Alliance For Digital Inclusion

21 June 2025

Access Holdings Reaffirms Financial Strength Amid CBN’s Regulatory Forbearance Directive

19 June 2025

Konga Health Sparks Nationwide Rush With 50% Discount On L’Oréal Products

17 June 2025

Comments are closed.

Categories
About
About

Digital Times Nigeria (www.digitaltimesng.com) is an online technology publication of Digital Times Media Services.

Facebook X (Twitter) Instagram
Latest Posts

BREAKING: Okonjo-Iweala Honoured With ACFE’s Highest Anti-Fraud Award

24 June 2025

Nominations Open As CIO & C-Suite Awards Africa 2025 Expands Across 15 African Countries

24 June 2025

IHS Nigeria, UNICEF Assess Lifesaving Impact Of Installed Oxygen Plant In Oyo State

24 June 2025
Popular Posts

Building Explainable AI (XAI) Dashboards For Non-Technical Stakeholders

2 May 2022

Building Ethical AI Starts With People: How Gabriel Ayodele Is Engineering Trust Through Mentorship

8 January 2024

Gabriel Tosin Ayodele: Leading AI-Powered Innovation In Web3

8 November 2022
© 2025 Digital Times NG. Designed by Max Excellence LLC.
  • Advert Rate
  • Terms of Use
  • Advertisement
  • Private Policy
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.