Canadian menswear chain Harry Rosen confirms cyber attack

Share post:

Canadian menswear retailer Harry Rosen has acknowledged being hit by a cyber attack last month.

This comes after the BianLian group listed the company as a victim on the gang’s site. The page lists “File server data. Projects, Marketing, HR, Public Relations,” which suggests these are files that have been copied and will potentially be released.

According to Brett Callow, a British Columbia-based threat analyst with Emsisoft, BianLian has released a 1GB file as proof of its attack. It claims the file is a list of Harry Rosen’s Gold+ clients, sales information, and various other types of documents.

In response to a query from IT World Canada, company CEO Larry Rosen sent this email on Friday morning: “We confirm that Harry Rosen was victim of a cyber attack that came to our attention on October 9th. Our network is now secure and we have been in regular communication with our customers and employees about the incident. We have also reported this to the police and to the federal privacy regulator and the privacy regulators in Alberta and Quebec.”

Asked in a follow-up to confirm that the attack was ransomware, and whether the attack affected company operations, Rosen said the retailer had no further comment.

Callow said the BianLian strain of ransomware was initially spotted in August. Little is known about this threat actor, he said, including what, if any, connections they may have to other cybercrime operations. Like most groups, Callow said, their targeting appears indiscriminate, with victims in multiple sectors including media and healthcare.

According to research from BlackBerry, BianLian ransomware, written for Windows systems in the Go language, “raises the cybercriminal bar by encrypting files with exceptional speed.”

BlackBerry believes this group targets corporations rather than specific countries. As of the time of the report, the listed victims on the gang’s site were in the United States, Australia, and the United Kingdom.

In the sample of the ransomware that BlackBerry looked at, the author packaged all the ransomware’s functionalities into a common package. Upon execution of the file, the application searches the host machine for all possible drive names. Once all the drives are populated with malware, the threat begins its ransom process. The ransomware encrypts files using the standard library crypto package in Go. These packages are open-source libraries used to provide cryptographic functionality, like the base CryptoAPI provided in Windows environments.

The ransomware targets any drive found on the system, including mounted drives, and encrypts anything that is not an executable, driver, or text file. These exclusions are meant to avoid encrypting either the ransom note, or anything that might cause the system to malfunction.

BlackBerry noted that research from another firm suggests the BianLian threat group’s initial access is likely gained via the Windows ProxyShell vulnerability chain or a SonicWall VPN firmware vulnerability. From there, the threat actor moves laterally to find targets of interest, escalates their privileges, and deploys the BianLian ransomware. Then, using dropped copies of WinSCP and 7-Zip to archive and transfer chosen files, data is extracted and sent back to the threat actor. Additionally, threat operators might install backdoors on the systems to maintain access to the infected system.

Founded in 1954, Harry Rosen is an upscale menswear chain with five stores in Toronto, as well as stores in B.C., Alberta, Quebec and Manitoba.

According to Digital Commerce, the company had sales of $300 million in 2020.

The post Canadian menswear chain Harry Rosen confirms cyber attack first appeared on IT World Canada.

Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Google Play introduces new biometric verification with a user warning

Google has recently announced updates to the biometric verification process for Google Play purchases, aiming to bolster security...

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways