Leaks: ADATA Storage Memory USB Chip Ransom Dumped

grarpamp grarpamp at gmail.com
Wed Jun 23 00:25:12 PDT 2021


Maybe some firmwares and tools for exploit researchers...

https://www.bleepingcomputer.com/news/security/adata-suffers-700-gb-data-leak-in-ragnar-locker-ransomware-attack/
http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/

The Ragnar Locker ransomware gang have published download links for
more than 700GB of archived data stolen from Taiwanese memory and
storage chip maker ADATA. A set of 13 archives, allegedly containing
sensitive ADATA files, have been publicly available at a cloud-based
storage service, at least for some time. [...] Two of the leaked
archives are quite large, weighing over 100GB, but several of them
that could have been easily downloaded are less than 1.1GB large. Per
the file metadata published by the threat actor, the largest archive
is close to 300GB and its name gives no clue about what it might
contain. Another large one is 117GB in size and its name is just as
nondescript as in the case of the first one (Archive#2). Judging by
the names of the archives, Ragnar Locker likely stole from ADATA
documents containing financial information, non-disclosure agreements,
among other type of details.

The ransomware attack on ADATA happened on May 23rd, 2021, forcing
them to take systems offline, the company told BleepingComputer. As
the Ragnar Locker leak clearly shows, ADATA did not pay the ransom and
restored the affected systems on its own. The ransomware actor claims
stealing 1.5TB of sensitive files before deploying the encryption
routine, saying that they took their time in the process because of
the poor network defenses. The recently leaked batch of archives is
the second one that Ragnar Locker ransomware publishes for ADATA. The
previous one was posted earlier this month and includes four small
7-zip archives (less than 250MB together) that can still be
downloaded.


More information about the cypherpunks mailing list