Skip to content
CTI Academy Sponsor CTI Academy
Ransomware victim Business Services

Four Hands LLC

Listed by 0mega on · organisation based in United States

fourhands.com

Disclosed
Jan 25, 2024
Leak-site listing date
Threat group
0mega
1 victims listed
Country
United States
#1 most targeted
Sector
Business Services

ThreatAI analysis

Compiled from this incident record and the threat intelligence profile for 0mega. Figures and technique mappings are quoted from the source data, not inferred.

About the 0mega group

0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts. 0mega has listed 7 victims since July 2022.

How 0mega is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference
Account Access Removal T1531 Impact

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place. In Windows, Net utility, <codeSet-LocalUser</code and <codeSet-ADAccountPassword</code PowerShell cmdlets may be used by adversaries to modify user accounts. Accounts could also be disabled by Group Policy. In Linux, the <codepasswd</code utility may be used to change passwords.

MITRE ATT&CK reference
Automated Collection T1119 Collection

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data. This functionality could also be built into remote access tools.

Mitigations: Remote Data Storage, Encrypt Sensitive Information

MITRE ATT&CK reference
Exfiltration Over C2 Channel T1041 Exfiltration

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Mitigations: Network Intrusion Prevention, Data Loss Prevention

MITRE ATT&CK reference
Data Encrypted for Impact T1486 Impact

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Mitigations: Data Backup, Behavior Prevention on Endpoint

MITRE ATT&CK reference

MITRE ATT&CK techniques attributed to 0mega across its recorded activity, not a finding about how Four Hands LLC was reached.

Incident analysis

Four Hands LLC was listed by 0mega ransomware, a group with 1 victims recorded in this database. The listing appeared on the group's leak site on January 25, 2024.

Four Hands LLC is based in United States and operates in the Business Services sector. United States ranks #1 worldwide for ransomware disclosures, with 9,971 victims in this database.

Sector context. Business services firms often have access to multiple client environments, making them high-value pivot points for ransomware operators seeking to maximise impact across multiple victim organisations.

0mega typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.

Frequently asked questions

Was Four Hands LLC attacked by ransomware?

Yes. Four Hands LLC was listed as a victim of the 0mega ransomware group on January 25, 2024. The organisation is based in United States and operates in the Business Services sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked Four Hands LLC?

Four Hands LLC was attacked by 0mega ransomware. 0mega is one of the most active ransomware groups, having claimed 1 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the Four Hands LLC ransomware attack occur?

The ransomware attack on Four Hands LLC was disclosed on January 25, 2024. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the Four Hands LLC ransomware attack?

The specific data stolen from Four Hands LLC has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Business Services organisation, Four Hands LLC likely held sensitive business data, client information, and operational records.

How can organisations protect against 0mega attacks?

To defend against 0mega and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.