Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
Title:
2013_011
Cyberattack targeting the maritime industry in several countries.
Day Month Year Country Activity Incident Type
01 March 2013 Australia Industry Virus/Ransomware

Summary

According to the source, between 2012 and 2013, a group attacked civilan and military operations in the US, Germany, Sweden, UK, Australia and other countries involved in maritime satellite systems, as well as defense contractors.

Victim

N/A

Claimed/Reported Threat Actor

Anchor Panda

Origin

Undisclosed

Main impact

Confidentiality

References

Recommendations to Industry to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks. Yes, there are no common and shared incident IDs in cyber (for now!).
Files generated on Thursday, 02nd November 2023.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2023.