Equinix data center giant hit by Netwalker Ransomware, $4.5M ransom
Datacenter and colocation giant Equinix has been hit with a Netwalker ransomware attack where threat actors are demanding $4.5 million for a decryptor and to prevent the release of stolen data.
Equinix is a massive data center and colocation provider with over 50 locations worldwide. Customers use these data centers to colocate their equipment or to interconnect with other ISPs and network providers.
Early this week, a source shared a Netwalker ransom note with BleepingComputer that was allegedly from an attack on Equinix that occurred over the Labor Day holiday weekend.
The company went public with a statement that says “Equinix is currently investigating a security incident we detected that involves ransomware on some of our internal systems. Our teams took immediate and decisive action to address the incident, notified law enforcement, and are continuing to investigate. Our data centers and our service offerings, including managed services, remain fully operational, and the incident has not affected our ability to support our customers. Note that as most customers operate their own equipment within Equinix data centers, this incident has had no impact on their operations or the data on their equipment at Equinix. The security of the data in our systems is always a top priority and we intend to take all necessary actions, as appropriate, based on the results of our investigation.”
Exposed remote desktop servers are the most common method used by hackers to compromise a network. After learning of this attack on Equinix earlier this week, BleepingComputer spoke to Advanced Intel’s Vitali Kremez about this attack,
According to Advanced Intel’s Andariel intelligence platform, there are 74 known Equinix remote desktop servers and their login credentials being sold in hacker marketplaces and private sales. Of the 74 remote desktop servers, most are concentrated in Australia, Turkey, and Brazil.
Reference:
Contact Us
Learn more about what Techcess CyberSecurity Group can do for your business.
1-833-TXCYBER
1-833-892-9237
Techcess CyberSecurity Group
6110 Clarkson Lane
Houston, Texas 77055
Techcess CyberSecurity Group
Houston, Texas 77055