Pandora Ransomware Targets Multiple Plants around the Globe

Threat Level – Amber | Vulnerability Report
Download PDF

For a detailed advisory, download the pdf file here

Pandora ransomware is a new operation that targets business networks and obtains data for double-extortion assaults and active since March 2022. DENSO, a Japanese auto parts manufacturer’s plant in Germany, and Global Wafers Japan, the world’s third-largest supplier of silicon wafers, both claim to have lost 1.4 TB and 1TB of data, respectively, as a result of this ransomware attack.

Attackers after gaining access to the infrastructure will do lateral movement through the network to steal unencrypted files which can be further utilized in extortion demands. The ransomware will attach the ‘.pandora’ extension to the encrypted file names. In addition to this, it will create ransom notes in every folder named ‘Restore_My_Files.txt’ that describes what happened to the device and provide an email address for victims to contact in order to negotiate a payment. A link to a data leak site used by the ransomware gang to execute their double-extortion activities is also included in the ransom notes. Due to code similarities and packers employed by the operation, this ransomware is suspected to be a rebrand of the Rook ransomware.

The Organizations can mitigate the risk by following the recommendations: •Keep all operating systems and software up to date. •Remove unnecessary access to administrative shares. •Maintain offline backups of data and Ensure all backup data is encrypted and immutable.

The MITRE TTPs commonly used by Pandora are:

TA0040: ImpactTA0042: Resource DevelopmentTA0002: ExecutionTA0003: Persistence       TA0004: Privilege EscalationTA0005: Defense Evasion       TA0008: Lateral MovementT1587: Develop CapabilitiesT1587.001: Develop Capabilities: MalwareT1059: Command and Scripting InterpreterT1055: Process InjectionT1070: Indicator Removal on HostT1112: Modify RegistryT1027: Obfuscated Files or InformationT1027.002: Obfuscated Files or Information: Software PackingT1021: Remote ServicesT1486: Data Encrypted for Impact

Actor Detail

Indicators of Compromise (IoCs)

Recent Breaches

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox