https://www.bleepingcomputer.com/news/security/costa-rica-declares-national-emergency-after-conti-ransomware-attacks/ BleepingComputer.com logo * * * [ ] [Login] [Sign up] * * * [ ] [Login] [Sign up] * News + Featured + Latest + Hackers exploiting critical F5 BIG-IP bug, public exploits released Hackers exploiting critical F5 BIG-IP bug, public exploits released + Ukraine warns of "chemical attack" phishing pushing stealer malware Ukraine warns of "chemical attack" phishing pushing stealer malware + Fake crypto giveaways steal millions using Elon Musk Ark Invest video Fake crypto giveaways steal millions using Elon Musk Ark Invest video + Costa Rica declares national emergency after Conti ransomware attacks Costa Rica declares national emergency after Conti ransomware attacks + Lincoln College to close after 157 years due ransomware attack Lincoln College to close after 157 years due ransomware attack + Hackers display "blood is on your hands Hackers display "blood is on your hands" on Russian TV, take down RuTube + Dell, Apple, Netflix face lawsuits for pulling services out of Russia Dell, Apple, Netflix face lawsuits for pulling services out of Russia + Microsoft releases fixes for Azure flaw allowing RCE attacks Microsoft releases fixes for Azure flaw allowing RCE attacks * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Virus Removal Guides + Latest + Most Viewed + Ransomware + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove the Smashapps.net Search Redirect Remove the Smashapps.net Search Redirect + Remove the Smashappsearch.com Search Redirect Remove the Smashappsearch.com Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Tutorials + Latest + Popular + How to make the Start menu full screen in Windows 10 How to make the Start menu full screen in Windows 10 + How to install the Microsoft Visual C++ 2015 Runtime How to install the Microsoft Visual C++ 2015 Runtime + How to open an elevated PowerShell Admin prompt in Windows 10 How to open an elevated PowerShell Admin prompt in Windows 10 + How to Translate a Web Page in Google Chrome How to Translate a Web Page in Google Chrome + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * Forums * More + Startup Database + Uninstall Database + File Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Security * Costa Rica declares national emergency after Conti ransomware attacks * * Costa Rica declares national emergency after Conti ransomware attacks By Ax Sharma * May 9, 2022 * 03:53 AM * 0 conti ransomware The Costa Rican President Rodrigo Chaves has declared a national emergency following cyber attacks from Conti ransomware group on multiple government bodies. BleepingComputer also observed Conti published most of the 672 GB dump that appears to contain data belonging to the Costa Rican government agencies. The declaration was signed into law by Chaves on Sunday, May 8th, same day as the economist and former Minister of Finance effectively became the country's 49th and current president. Costa Rica under national emergency after cyberattacks On Sunday, May 8th, the newly elected Costa Rican President Chaves declared a national emergency citing ongoing Conti ransomware attacks as the reason. Conti ransomware had originally claimed ransomware attack against Costa Rican government entities last month. The country's public health agency Costa Rican Social Security Fund (CCSS) had earlier stated that "a perimeter security review is being carried out on the Conti Ransomware, to verify and prevent possible attacks at the CCSS level." En este momento se realiza revision en la seguridad perimetral sobre el Ransomware Conti, para verificar y prevenir posibles ataques a nivel de la CCSS. -- CCSSdeCostaRica (@CCSSdeCostaRica) April 19, 2022 BleepingComputer observed that as of yesterday Conti's data leak site had been updated to state that the group had leaked 97% of the 672 GB data dump allegedly containing information stolen from government agencies: Conti leak site with stolen data allegedly belonging to Costa Rica Conti appears to have leaked 97% of stolen 672 GB data dump (BleepingComputer) The public body that first suffered damage from Conti's cyberattack is the Ministry of Finance which still has not yet fully evaluated the scope of the security incident or to what extent has taxpayers' information, payments, and customs systems have been impacted. Conti earlier demanded a $10 million ransom from the Ministry which the government declined to pay, according to Swissinfo.ch. Conti's leak site presently lists the following government purportedly affected by the attack, as seen by BleepingComputer: * The Costa Rican Finance Minsitry, Ministerio de Hacienda * The Ministry of Labor and Social Security, MTSS * The Social Development and Family Allowances Fund, FODESAF * The Interuniversity Headquarters of Alajuela, SIUA BleepingComputer has not yet analyzed the leaked data but a preliminary analysis of a very small subset of the leaked data shows source code and SQL databases that appears to be from government websites. Rather than attributing this cyberattack to nation-state hackers, Conti threat actor "UNC1756," along with their affiliate, has solely claimed responsibility for it. The threat actor has threatened to conduct future attacks of "a more serious form." News outlet Amelia Rueda that earlier reported on the development states the execute decree No. 42542 from the President establishes an emergency: "The attack that Costa Rica is suffering from cybercriminals, cyberterrorists is declared a national emergency and we are signing this decree, precisely, to declare a state of national emergency in the entire public sector of the Costa Rican State and allow our society to respond to these attacks as criminal acts," said the President, accompanied by Minister of the Presidency, Natalia Diaz, and the Minister of Science, Innovation, Technology and Telecommunications (Micitt), Carlos Alvarado. Since April 18th, the Treasury's digital services have been unavailable which is affecting the entire "productive sector" due to government procedures, signatures, and stamps having been disrupted, reports, Amelia Rueda. "We signed the decree so that the country can defend itself from the criminal attack that cybercriminals are making us. That is an attack on the Homeland and we signed the decree to have a better way of defending ourselves," added President Chaves. Other agencies to have been impacted by Conti's attacks include: * Administrative Board of the Electrical Service of the province of Cartago (Jasec) * The Ministry of Science, Innovation, Technology, and Telecommunications * National Meteorological Institute (IMN) * Radiographic Costarricense (Racsa) * Costa Rican Social Security Fund (CCSS). As reported by BleepingComputer last week, the U.S. government is rewarding up to $15 million to anyone providing information that can lead to the identification and arrests of Conti ransomware's leadership and operators. The U.S. Department of State pledged to offer up to $10 million for information on the identity and location of the threat actors with an additional $5 million bounty for leading to the arrest and/or convictions of the individuals responsible for these attacks. Conti ransomware group in review Conti is a Ransomware-as-a-Service (RaaS) operation linked to the Russian-speaking Wizard Spider cybercrime group (also known for other notorious malware, including Ryuk, TrickBot, and BazarLoader). The cybercrime gang's victims include Ireland's Health Service Executive (HSE) and its Department of Health (DoH), asking the former to pay a $20 million ransom. The FBI also warned in May 2021 that Conti operators tried to breach over a dozen US healthcare and first responder organizations. In August 2021, a disgruntled affiliate leaked Conti's training materials, including info on one of its operators, a manual on deploying various malicious tools, and numerous help documents allegedly provided to the group's affiliates. According to analysts from multiple cybersecurity firms, Conti is now managing various side businesses meant to sustain its ransomware operations or pay for initial network access when needed. One such side operation is the recently emerged Karakurt data extortion group, active since at least June 2021 and recently linked to Conti by researchers from Advanced Intelligence, Infinitum, Arctic Wolf, Northwave, and Chainalysis, as the cybercrime gang's data extortion arm. Related Articles: Wind turbine firm Nordex hit by Conti ransomware attack Hackers use Conti's leaked ransomware to attack Russian companies Shutterfly services disrupted by Conti ransomware attack US offers $15 million reward for info on Conti ransomware gang The Week in Ransomware - May 6th 2022 - An evolving landscape * Conti * Costa Rica * Cyberattack * Emergency Declaration * Government * Politics * Ransomware * * * * * Ax Sharma Ax Sharma is a Security Researcher and Tech Reporter. His works and expert analyses have frequently been featured by leading media outlets including Fortune, Business Insider, The Register, TechRepublic, etc. Ax's expertise lies in vulnerability research, malware analysis, and open source software. He's an active community member of the OWASP Foundation, Open Source Security Foundation (OpenSSF), and the British Association of Journalists (BAJ). Send any tips via email or Twitter DM. * Previous Article * Next Article Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] [FP_FinServ_Bleeping-Computer_400x500] Popular Stories * F5 Exploits created for critical F5 BIG-IP flaw, install patch immediately * Hacker threat actor Hackers are now hiding malware in Windows Event Logs Newsletter Sign Up To receive periodic updates and news from BleepingComputer, please use the form below. [ ] [Submit] [739-PCWorl] Newsletter Sign Up [ ] [Submit] * Follow us: * * * * Main Sections * News * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * File Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement Copyright @ 2003 - 2022 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT