News

DopplePaymer ransomware operators hacked NASA contractor

DopplePaymer ransomware operators congratulated SpaceX and NASA on the successful launch of their first private manned ship, and then reported that they hacked and infected the network of Digital Management Inc (DMI), NASA contractor.

According to official figures, the DMI customer list includes a number of Fortune 100 companies, and many government agencies and NASA are among them.

Recall that earlier DopplePaymer operators published in the public domain Boeing, Lockheed Martin, SpaceX and Tesla documents.

ZDNet reports that it is still unclear how deeply hackers were able to penetrate the network of the company, and how many machines were damaged by the DopplePaymer attack. Journalists were not able to contact DMI representatives.

“The thing that appears to be clear is that they got their hands on NASA-related files, suggesting they breached DMI’s NASA-related infrastructure”, — report ZDNet journalists.

To confirm their statements, DoppelPaymer operators posted 20 archives with stolen data on the site.

These archives contain a wide variety of information, from HR documents to project plans. The DMI employee information that can also be found in these files, which match to public records on LinkedIn.

The criminals also unveiled a list of 2583 servers and workstations, which they claim to be part of the DMI internal network. Allegedly, all these machines were encrypted, and now the group requires a ransom for their decryption.

The DopplePaymer Ransomware team is one of several ransomware gangs that also deal with data leaks. They periodically publish the data of hacked companies and require money from attacked companies, threating to made information public.

“DopplePaymer operators first share small samples like the one they shared today, and in case the victim isn’t intimidated and still refuses to pay the file decryption fee, they leak all files as revenge”, – says ZDNet magazine.

This ransomware tactic has been used since December 2019, but today it seems that cybercriminals have moved to a new level: the ransomware operators REvil (Sodinokibi) launched an auction site similar to eBay, where they are going to sell the stolen data of the victims.

Apparently, the criminals made this decision after they managed to steal the confidential data of show business stars who are clients of the law firm Grubman Shire Meiselas & Sacks.

User Review
0 (0 votes)
Comments Rating 0 (0 reviews)
James Brown

Technology news writer and part-time security researcher. Author of how-to articles related to Windows computer issue solving.

View Comments

  • […] захисту: є приклади цілком реальних атак, наприклад, ЗМІ писали про те, що оператори шифрувальників DopplePaymer зламали […]

Recent Posts

Remove News-bpudepi.today pop-up ads (Virus Removal Guide)

News-bpudepi.today is a domain that tries to trick you into subscribing to its browser notifications…

18 hours ago

Remove Doguhtam.xyz pop-up ads (Virus Removal Guide)

Doguhtam.xyz is a site that tries to trick you into subscribing to its browser notifications…

18 hours ago

Remove News-xlixoti pop-up ads (Virus Removal Guide)

News-xlixoti.com is a site that tries to force you into subscribing to its browser notifications…

18 hours ago

Remove Ducesousightion pop-up ads (Virus Removal Guide)

Ducesousightion.com is a domain that tries to trick you into clik to its browser notifications…

18 hours ago

Remove News-xlabica.live pop-up ads (Virus Removal Guide)

News-xlabica.live is a domain that tries to trick you into clik to its browser notifications…

18 hours ago

Remove Mergechain.co.in pop-up ads (Virus Removal Guide)

Mergechain.co.in is a site that tries to trick you into subscribing to its browser notifications…

18 hours ago