AusProof is a mining industry firm specialising in the design and manufacture of low- and high-voltage electrical cable couplers for tunnelling and mining. The company was established in 1994 and is based in Gladstone, Queensland, and serves clients around the world.
The company was listed on the dark web leak site of the M3rx ransomware gang, which claimed to have exfiltrated data from the company’s systems.
While the threat actor did not go into detail about the cyber incident, it did claim to have stolen 460 gigabytes of data, equating to 373,495 files. It also shared a file list containing a list of the data the group claims to have exfiltrated.
The group has not said when the data will be leaked or set a public ransom amount.
Cyber Daily has reached out to AusProof for more information.
Who is M3rx?
M3rx is a newcomer to the ransomware scene, having first been observed around April and May this year.
The location of its victims is typically diverse, with organisations from England, the United States, Australia, Germany, Italy, and Switzerland.
While little else is known about the group at this time, researchers at IBM X-Force Exchange have gathered a small amount of intelligence on its actual ransomware variant.
“The ransomware uses a PE32+ x64 Go sample, which includes an embedded config, writes a ransom note named RECOVERY_NOTES.TXT, renames encrypted files with a .8hmlsewu extension, and deletes itself through PowerShell after execution. M3rx employs X25519 key exchange, AES-CTR for file content, and AES-GCM to wrap each per-file AES key, with a fixed 0x400-byte footer,” IBM’s security people said.
“The encryptor’s file format is recognisable, and the public trail is still developing. The ransom note claims files were stolen and encrypted, demanding bitcoin after negotiation and threatening publication. The sample shows file-impact behaviours such as encryption, note dropping, Recycle Bin clearing, and self-delete behaviour. Detection artifacts include specific SHA256 and MD5 hashes, embedded config details, and unique strings.”
In May, the group listed Prime Properties, a property investment firm, and claimed to have stolen 100 gigabytes of data, totalling at least 81,000 files.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.