Trending

ee-track">
HomeBlog
​BlackMatter Ransomware Attack Impacting Multiple Financial Institutions
Cyble-BlackMatter-Ransomware-Financial-Information-Pine-Labs

​BlackMatter Ransomware Attack Impacting Multiple Financial Institutions

Cyble's Research on a ransomare attack by BlackMatter, exposing financial information of several institutions across India.

In the course of our routine threat hunting exercise, the Cyble Research Lab discovered that Pine Labs, an Indian merchant platform company that provides financing and last-mile retail transaction technology, was impacted by a ransomware attack. Our investigation showcased that the BlackMatter ransomware group is behind the attack on Pine Labs. The group has been garnering considerable media attention because of this attack.  

On August 5, 2021, Cyble Research Labs published a detailed technical analysis of the BlackMatter ransomware group. Cyble also covered BlackMatter’s activities separately, wherein the group was recruiting via cybercrime forums and seeking affiliates. 

The attack came into the limelight after the BlackMatter ransomware group updated its victim list on its leak website on August 10, 2021. The impact of this attack is significant, as initial investigations indicate that the incident has affected multiple financial institutions using Pine Labs services across India. 

Analysis  

Upon further analysis, we found that the attack exposed the following details: 

  • Service and other private agreements between multiple Indian banks/institutions and Pine Labs 
  • Multiple financial reports  
  • More than 500,000 unique records of contact information (leads): phone, name, e-mail 
Cyble BlackMatter Ransomware Financial Information Pine Labs Post by BlackMatter
Figure 1 Post by BlackMatter

Figures 2 and 3 shows the list of affected entities. 

Cyble BlackMatter Ransomware Financial Information Pine Labs Sample Data Showcasing Affected Banks
Figure 2 Sample Data Showcasing Affected Banks 
image 29
Figure 3 Sample Data Showcasing Affected Banks 

Based on further analysis, we found that the data shared by the ransomware group contains their internal documents such as agreements with multiple institutions and other confidential information, as shown in Figures 4 and 5.   

report-ad-banner
Cyble BlackMatter Ransomware Financial Information Pine Labs Internal Document
Figure 4 Pine Labs Internal Document
Cyble BlackMatter Ransomware Financial Information Pine Labs Employee Details
Figure 5 Pine Labs Employee Details
Cyble BlackMatter Ransomware Financial Information Pine Labs Sample Data 3 1
Figure 6 Sample Data

Conclusion  

Ransomware groups continue to pose a serious threat to firms and individuals. Organizations need to stay ahead of the techniques used by Threat Actors. Victims of ransomware are at the risk of losing valuable data, which can further lead to financial loss and loss of reputation and productivity.  

Cyble Research Lab is continuously monitoring the activities of the BlackMatter ransomware group, and we will keep updating this space with new information.  

Our Recommendations 

  • Use the shared IoCs to monitor and block the malware infection. 
  • Use strong passwords and enforce multi-factor authentication wherever possible.  
  • Turn on the automatic software update feature on your computer, mobile, and other connected devices wherever possible and pragmatic.  
  • Use a reputed anti-virus and Internet security software package on your connected devices, including PC, laptop, and mobile.  
  • Refrain from opening untrusted links and email attachments without verifying their authenticity. 

Indicators of Compromise (IoCs):   

Indicators Indicator type Description 
daed41395ba663bef2c52e3d1723ac46253a9008b582bb8d9da9cb0044991720 Hash SHA-256 
c6e2ef30a86baa670590bd21acf5b91822117e0cbe6060060bc5fe0182dace99 Hash SHA-256 
7f6dd0ca03f04b64024e86a72a6d7cfab6abccc2173b85896fc4b431990a5984 Hash SHA-256 
22d7d67c3af10b1a37f277ebabe2d1eb4fd25afbd6437d4377400e148bcc08d6 Hash SHA-256 
mojobiden.com URL TA C2 
paymenthacks.com URL TA C2 
http:[//]supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid[.]onion TOR URL TA Contact URL 

Disclaimer 

Cyble Research Lab is continuously monitoring the activities of the BlackMatter ransomware group, and we will keep updating this space with new information. Please also check the two advisories posted on Cyble Vision for a detailed analysis of the ransomware group

About Us 

Cyble is a global threat intelligence SaaS provider that helps enterprises protect themselves from cybercrimes and exposure in the Darkweb. Its prime focus is to provide organizations with real-time visibility to their digital risk footprint. Backed by Y Combinator as part of the 2021 winter cohort, Cyble has also been recognized by Forbes as one of the top 20 Best Cybersecurity Start-ups To Watch In 2020. Headquartered in Alpharetta, Georgia, and with offices in Australia, Singapore, and India, Cyble has a global presence. To learn more about Cyble, visit https://cyble.com 

Disclaimer: This blog is based on our research and the information available at the time of writing. It is for informational purposes only and does not constitute legal, financial, or professional advice. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. If any sensitive information has been inadvertently included, please contact us for correction. Cyble is not responsible for any errors, omissions, or decisions made based on this content. Readers should verify findings and seek expert advice where necessary. All trademarks, logos, and third-party content belong to their respective owners and do not imply endorsement or affiliation. All content is presented “as is” without any guarantee that it is free of confidential, proprietary, or otherwise sensitive information. If you believe any portion of this content contains inadvertently shared or sensitive data, please contact us immediately so that we may address and rectify the issue. No Liability for Errors or Omissions Due to the dynamic nature of cyber threat activity, this [blog/report/article] may include partial, outdated, or otherwise incorrect information due to unverified sources, evolving security threats, or human error. We expressly disclaim any liability for errors or omissions or any potential consequences arising from the use, misuse, or reliance on this information.

Get Threat Assessment Report

Identify External Threats Targeting Your Business​
Free
CISO's Guide to Threat Intelligence 2024

CISO’s Guide to Threat Intelligence 2024: Best Practices

Stay Ahead of Cyber Threats with Expert Insights and Strategies. Download Free E-Book Now

Stay informed

Subscribe to Cyble

Get the latest threat intelligence, research, and security updates straight to your inbox.

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Share the Post:
Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams