Circus Spider

Description

(Carbon Black) MailTo is a ransomware variant that has recently been reported to have been part of a targeted attack against Toll Group, an Australian freight and logistics company. This ransomware makes no attempt to remain stealthy, and quickly encrypts the user’s data as soon as the ransomware is launched. Once the encryption phase completes, the encrypted files are renamed to contain the word “mailto”, which is where the name originated from.

Names

NameName-Giver
Circus SpiderCrowdStrike

Country

Motivation

  • Financial gain

First Seen

2019

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Other Information

Uuid

0de32c9a-cacb-4de5-84c5-866625288f24

Last Card Change

2024-12-27