Trending

ee-track">
Link copied!

Nefilim Ransomware Operators Strikes Brazilian Conglomerate, Cosan — Data Leaked

In another data breach incident, the Nefilim Ransomware operators have leaked the data of Cosan. About Cosan: Cosan is a public listed company, a Brazilian conglomerate producer of bioethanol, sugar and energy. According to Reuters, the company’s…

March 31, 2020 · 2 min read
Nefilim Ransomware Operators Strikes Brazilian Conglomerate, Cosan — Data Leaked

In another data breach incident, the Nefilim Ransomware operators have leaked the data of Cosan.

About CosanCosan is a public listed company, a Brazilian conglomerate producer of bioethanol, sugar and energy. According to Reuters, the company’s segments include Raizen Energia, Raizen Combustiveis, COMGAS, Cosan Logistica, Lubricants and Other business. The company’s other business includes other investments, in addition to corporate activities. The company offers Logistics services, including transportation, port loading and storage of sugar, leasing or lending of locomotives, wagons and other railway equipment, through its subsidiaries Rumo Logistica Operadora Multimodal S.A. (Rumo), logistic segment (Logistic).

Based on the information leaked, it appears the negotiation between the ransomware operators and Cosan failed, which lead to this leak.

Below is the message from the operators themselves:

1*65x1P9pzu0G0 DWamz978A
The original message from the Nefilim operators

Cyble research team has verified the leak (over 3.1GB compressed). The directory listing is available here (it’s likely to be taken down at some point) — https://uploadfiles.io/4n36xyx7

Update: On April 1, 2020, the group leaked the second part of their leak (over 5.2GB compressed) as below:

report-ad-banner
1*Ugnct7MCSRC0Xv59pQJ83w

Update: On April 22, 2020, the group leaked the third part of their leak (around 20GB) as below:

image 3
image 6
Snapshot of files being leaked in data leak part 3

About Cyble:

Cyble Inc.’s mission is to provide organizations with a real-time view of their supply chain cyber threats and risks. Their SaaS-based solution powered by machine learning and human analysis provides organizations’ insights to cyber threats introduced by suppliers and enables them to respond to them faster and more efficiently.

Cyble strives to be a reliable partner/facilitator to its clients allowing them with unprecedented security scoring of suppliers through cyber intelligence sourced from open and closed channels such as OSINT, the dark web and deep web monitoring and passive scanning of internet presence. Furthermore, the intelligence clubbed with machine learning capabilities fused with human analysis also allows clients to gain real-time cyber threat intel and help build better and stronger resilience to cyber breaches and hacks. Due to the nature of the collected data, the company also offer threat intelligence capabilities out-of-box to their subscribers.

THIS POST HAS BEEN EXPORTED FROM OUR MEDIUM CHANNEL

AI Threat Intelligence

Stop Executive Threats
Before They Strike

Monitor dark web chatter, detect lookalike domains, and protect your C-suite from targeted impersonation — in real time, across 50+ countries.

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams