By Gregory Hale
Colombian energy company Empresas Públicas de Medellín (EPM) suffered a BlackCat/ALPHV ransomware attack last month, which ended up affecting financial operations and taking down online services.
EPM is one of Colombia’s largest public energy, water, and gas providers, providing services to 123 municipalities. The company generated over $25 billion in revenue in 2022 and is owned by the Colombian Municipality of Medellin.
On December 13, the company told 4,000 employees to work from home, with IT infrastructure down and the company’s websites no longer available. EPM said the company was responding to a cybersecurity incident and provided alternative methods for customers to pay for services.
In a translated report, the attack occurred at dawn on December 13, the day before the first two Hidroituango turbines at the facility generated energy for the first time. The company learned it no longer had a website, mobile application, payment gateway or intranet. Also, computers connected to the smart building network did not turn on or were blocked.
In a brief statement, the company said they had had a “cybersecurity incident,” which is why they had sent their employees home and assured the situation had “no affect on the adequate provision of public services of energy, water and gas.”
The Prosecutor’s Office confirmed to the EL COLOMBIANO publication ransomware was behind the attack on EPM that caused devices to be encrypted and data to be stolen.
However, the ransomware operation behind the attack was not disclosed.
However, BleepingComputer learned the BlackCat ransomware operation, aka ALPHV, was behind the attacks, claiming to have stolen corporate data during the attacks.
BleepingComputer has also seen the encryptor sample and ransom notes from the EPM attack and has confirmed they are from the BlackCat ransomware operation.
“ALPHV/BlackCat maintain a data leak site where they host stolen data to further extort all of their victims,” said Daniel Mayer, threat researcher at security provider, Stairwell. “Nothing is out of the ordinary with their data exfiltration tactics here. Although other versions of Exmatter analyzed have had evidence of data destruction capabilities, it looks like in this case it was merely used to exfiltrate data before deploying ALPHV ransomware. Stairwell’s threat research team talked with the ALPHV admin over a messaging service, where the admin stated they are planning to use data destruction as a tactic more when EDR prevents them from deploying ransomware. In our report on Exmatter, we illustrate how Exmatter is designed to corrupt file data using other files on the victim machine, potentially as a way to avoid EDR heuristics.
“These groups must be detected and ousted from a company’s network before they are at the point where they can deploy ransomware. This means detecting all the steps leading up to data extortion, such as phishing or the exploitation known vulnerabilities as the initial point of entry, the installation of remote administration tools or post-exploitation frameworks, and the escalation of privileges through credential dumping and lateral movement until they reach domain admin. All of these actions make noise that can be caught in a timely manner with adequate detection and hunting capabilities,” Mayer said. “A commonality amongst all ransomware intrusions is that the threat actor must become domain administrator to deploy their ransomware enterprise-wide.”

