Managed Services provider CompuCom by Darkside ransomware

US managed service provider CompuCom was the victim of a cyberattack that partially disrupted its operations, experts believe it was a ransomware attack.

US managed service provider CompuCom was the victim of a cyberattack that partially disrupted its services and some of its operations. Even if the company initially did not provide technical details about the attack, security experts speculated the involvement of ransomware due to the observed effects.

The provider is a wholly-owned subsidiary of The ODP Corporation, it provides Managed Workplace Services including IT solutions and hardware and software resale, integration, and support services. 

According to BleepingComputer, the company was the victim of a ransomware attack conducted by the Darkside ransomware gang.

“Certain CompuCom information technology systems have been affected by a malware incident which is affecting some of the services that we provide to certain customers. Our investigation is in its early stages and remains ongoing. We have no indication at this time that our customers’ systems were directly impacted by the incident.” reads the statement launched by the company.

As soon as we became aware of the situation, we immediately took steps to contain it, and engaged leading cybersecurity experts to begin an investigation. We are also communicating with customers to provide updates about the situation and the actions we are taking. We are in the process of restoring customer services and internal operations as quickly and safely as possible. We regret the inconvenience caused by the interruption and appreciate the ongoing support of our customers.

CompuCom confirmed that its systems were infected with malware that impacted its services, the provider immediately launched an investigation into the incident.

At the time of this writing, the ongoing investigation did not provide any evidence that customers’ systems were directly impacted by the attack.

CompuCom later shared a ‘Customer FAQ Regarding Malware Incident’ that provides additional technical details about the attack, such as the use of Cobalt Strike beacons on several systems in their environment. 

“Based on our expert’s analysis to date, we understand that the attacker deployed a persistent Cobalt Strike backdoor to several systems in the environment and acquired administrative credentials,” the CompuCom FAQ reads, according to BleepingComputer. “These administrative credentials were then used to deploy the Darkside Ransomware.”

DarkSide Ransomware gang usually steals data before encrypting the victims’ systems, which means that it is possible that the threat actors have also exfiltrated company data.

At the time of this writing, the data from CompuCom has yet to be published on the DarkSide gang’s leak site.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

Pierluigi Paganini

(SecurityAffairs – hacking, CompuCom)

The post Managed Services provider CompuCom by Darkside ransomware appeared first on Security Affairs.

Security Affairs


Are you looking for products for hacking, cybersecurity, and penetration testing? Do you need to cleanse your smartphone, PC, or website from viruses and malware? Do you need to track down a person or recover urgent information? Do you need to regain control of an account, email, or password that has been stolen from you? Interested in purchasing pre-configured devices to easily and quickly experiment with hacking techniques? Do you have specific requirements in software or hardware? We can assist you!

Contact us immediately for immediate assistance: provide us with details via email or WhatsApp about the type of support you need, and we will respond you promptly!

Fill out and submit the form below to send us an immediate support request

Write your email address here

Write here how we can help you - we provide immediate support for all your needs!

chevron_left
chevron_right