Hellcat, the ransomware crew that infected Schneider Electric and demanded $125,000 in baguettes, has aggressively targeted government, education, energy, and other critical industries since it emerged around mid-2024. Like many of the emerging cybercrime organizations, Hellcat uses a ransomware-as-a-service business model, offering infrastructure, encryption tools, and other malware to affiliates in exchange for a portion of the profits. Its primary operators seem to be high-ranking BreachForums members [PDF]. Hellcat also uses double-extortion tactics, as do most ransomware gangs these days. First, it breaks into victims' networks and steals their files, then it locks up the data and threatens to leak or sell sensitive information if the organization doesn't pay the extortion demand. But what makes this group especially concerning, according to threat researchers, is its high-profile targets and penchant for humiliating its victims. This was the case with the November Schneider Electric attack, during which the criminals claimed to have stolen 40GB of compressed data. Before leaking 75,000 email addresses and full names of Schneider Electric employees and customers, Hellcat demanded that the French energy management giant pay $125,000 in baguettes. Humiliation is a major psychological tactic leveraged by Hellcat The move was intended "to further mock the company," Cato Networks Chief Security Strategist Etay Maor said in a report published on Tuesday. "Humiliation is a majo...
Baguette bandits strike again with ransomware and a side of mockery
The Register
·Jessica Lyons
·Published Jan 28, 2025
·Updated
Affected Software
2 affected components
Atlassian Jira
Schneider Electric Electric
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the ransomware group Hellcat, notorious for targeting critical industries and demanding payment in baguettes.
2
What security implications are discussed?
The article highlights the increasing threat posed by ransomware attacks on vital sectors such as government, education, and energy.
3
What products or software are affected by the ransomware attacks?
The article mentions that Atlassian Jira and Schneider Electric's software are among those impacted by the Hellcat ransomware attacks.
4
When did the ransomware group Hellcat first emerge?
Hellcat first emerged around mid-2024 and has since aggressively targeted various industries.
5
What unique demand did Hellcat make in their ransom note?
The ransomware group Hellcat demanded payment specifically in baguettes, adding a layer of mockery to their criminal activities.