ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Data Breaches

China Energy Giant, CEEC, Falls Victim to Rhysida Ransomware Attack

Kyle by Kyle
November 26, 2023 - Updated on December 16, 2023
in Data Breaches, Malware
Reading Time: 2 mins read
State-owned China Energy Engineering Corp (CEEC) hit by Rhysida ransomware; global alert issued. Insights into tactics and impact on #StopRansomware effort
54
SHARES
865
VIEWS
Share on FacebookShare on Twitter

In a recent development, the China Energy Engineering Corporation (CEEC), a state-owned entity operating in China’s energy and infrastructure sectors, has fallen victim to the Rhysida ransomware gang. The notorious cybercriminal group, known for its disruptive activities since May 2023, has added CEEC to its list of targets on its Tor leak site.

https://twitter.com/ransomfeed/status/1728504528083816811

CEEC, as one of China’s leading integrated energy companies, holds a significant position within the industry. It actively engages in the development and construction of diverse energy projects, spanning coal, hydropower, nuclear, and renewable energy initiatives. Beyond its national operations, CEEC also contributes to global energy landscapes through participation in international projects.

Rhysida Ransomware attack hits CEEC China Energy

The Rhysida ransomware gang, which has recently expanded its list of victims to include institutions like the British Library, claims to have acquired a substantial cache of valuable data. This data is purportedly up for auction at the price of 50 Bitcoin. Notably, the group intends to sell the stolen information to a single buyer and plans to release it publicly over a seven-day period following the announcement.

This incident comes on the heels of a joint Cybersecurity Advisory (CSA) issued by the FBI and CISA as part of the ongoing #StopRansomware initiative. The advisory serves to alert organizations to the tactics, techniques, and procedures (TTPs) associated with ransomware groups, including Rhysida. It contains indicators of compromise (IOCs) identified through investigations as recent as September 2023.

The Rhysida ransomware group has targeted a broad spectrum of industries, affecting at least 62 companies. The victims range from the education and healthcare sectors to manufacturing, information technology, and government entities. These attacks are characterized as striking “targets of opportunity,” as detailed in the joint advisory.

The group’s modus operandi involves leveraging Rhysida ransomware to impact various sectors, with similarities noted between their activities and those of Vice Society (DEV-0832). Furthermore, the report reveals instances of Rhysida actors operating in a ransomware-as-a-service (RaaS) capacity. In this model, ransomware tools and infrastructure are leased out, with profits from paid ransoms shared between the group and its affiliates.

Rhysida actors employ several techniques for initial access and persistence within target networks. External-facing remote services, such as VPNs and RDPs, are exploited for initial access, while compromised credentials are used to authenticate internal VPN access points. The threat actors have also taken advantage of the Zerologon vulnerability in Microsoft’s Netlogon Remote Protocol through phishing attempts.

Living off-the-land techniques, utilizing native network administration tools built into the operating system, are a key aspect of the group’s malicious operations, according to the advisory. The ongoing activities of the Rhysida ransomware gang underscore the persistent and evolving threat landscape organizations face in the realm of cybersecurity.

Tags: chinaransomwareRhysida
Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Panera Bread Hacked – Exposes 5.1 Million Customer Records

Panera Bread Hacked – Exposes 5.1 Million Customer Records

February 8, 2026
Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026

Tennessee Man Pleads Guilty to Posting Stolen SCOTUS Docs on Instagram

January 19, 2026
Next Post
Crisis at Ardent Health: Ransomware attack disrupts operations, forcing patient diversions. The Tennessee-based provider initiates cybersecurity measures.

Cybersecurity Crisis Hits Ardent Health Services

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.