Menu
Browse

Cyber Incident Victim: Italian Compression Solutions

Date:

Jun 2019

Location:

Italy

Summary

The Winrar.it distributor site was compromised to distribute Sodinokibi ransomware, part of a broader campaign leveraging multiple infection vectors including hacked managed service provider (MSP) tools, malicious spam emails impersonating Booking.com, and compromised software distribution platforms. Attackers deployed the ransomware through techniques such as exploiting MSP management consoles to push payloads, weaponized Word documents delivering PowerShell scripts, and hijacking legitimate websites to redirect victims. These activities resulted in widespread file encryption and ransom demands, with affiliates capitalizing on the void left by discontinued ransomware operations to propagate Sodinokibi across diverse targets.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

The Sodinokibi ransomware campaign involving the Winrar.it distributor site occurred in mid-June 2019 as part of a broader affiliate-driven operation filling the void left by GandCrab's shutdown. Attackers compromised the legitimate Winrar.it software distribution website to deliver malicious payloads, leveraging the site's trusted status to infect visitors. This method operated alongside two other parallel infection vectors: compromised Managed Service Provider (MSP) platforms including Webroot, Kaseya VSA, and ConnectWise, which attackers used to push ransomware through management consoles, and Booking.com-themed spam emails distributing weaponized Word documents. In the Winrar.it compromise, threat actors altered the site to facilitate ransomware deployment, though specific technical details of the website modification were not disclosed in available sources. The final payload involved PowerShell scripts hosted on Pastebin that downloaded and executed Sodinokibi ransomware binaries.

Cyber Incident Image

The ransomware encrypted victims' files across compromised systems, rendering data inaccessible until ransom payments were made. Security researchers observed the campaign's rapid propagation through these multiple vectors, noting its operational maturity in mimicking legitimate traffic and infrastructure. No specific victim count or industry targeting was detailed for the Winrar.it component, though the broader campaign affected MSP clients and spam email recipients. Response actions were limited to industry detection and analysis, with security firms documenting the attack patterns and infrastructure. The incident highlighted ransomware affiliates' adaptability in exploiting software supply chains, trusted business platforms, and phishing lures simultaneously to maximize infection rates. Financial impacts stemmed directly from operational disruption and ransom demands against affected entities.

Sources
Sources available to members
1 source