BestSeller Ransomware Attack
What does three weeks of advance warning buy you? This case study follows Blackwired's tracking of a ransomware campaign targeting BestSeller, the Danish fashion company, from the first dark web signal in October 2024 to the Fortijump exploit weeks later. See how the ThirdWatch Aim, Ready, Fire model and Direct Threat Intelligence identified adversary infrastructure early and delivered containment measures.
What happened in the BestSeller ransomware incident?
In late 2024, BestSeller, a Danish fashion company, was targeted by a ransomware campaign that Blackwired had been tracking weeks in advance.
Timeline of events:
- October 18, 2024 – Early reconnaissance: Blackwired detected suspicious activity linked to the GandCrab dark web domain. This was the reconnaissance stage and provided roughly three weeks of lead time before the confirmed attack.
- By November 8, 2024 – Infrastructure setup: Blackwired’s ThirdWatch Direct Threat Intelligence (DTI) identified a surge in malicious activity, including 42 new executables and 202 ransomware variants such as Expiro, Moiva, and Ryuk. Indicators showed consistent use of malicious IPs, URLs, and domains, including the download of a poisoned Fortinet operating system from an illegitimate site.
- November 13, 2024 – Attack confirmed: BestSeller confirmed a ransomware attack exploiting the Fortijump vulnerability. A robotic wave attack validated Blackwired’s earlier prediction.
Throughout this period, Blackwired used its Aim, Ready, Fire (ARFi) anticipatory risk model to track the adversary’s infrastructure and actions. Blackwired repeatedly provided BestSeller with DTI-based containment and remediation guidance. However, BestSeller chose not to implement the recommended FastHunt DTI remediations pre-emptively, which limited the opportunity to contain the threat before it fully materialized.
How did Blackwired detect and track the ransomware threat?
Blackwired relied on its ThirdWatch Direct Threat Intelligence (DTI) platform and the Aim, Ready, Fire (ARFi) anticipatory risk model to detect and track the threat in stages.
1. Aim phase – Early threat detection
- On October 18, 2024, Blackwired detected early reconnaissance activity tied to the GandCrab dark web domain.
- This provided about three weeks of pre-incident lead time for BestSeller to prepare and implement containment measures.
2. Ready phase – Infrastructure setup
- By November 8, 2024, ThirdWatch DTI showed a clear escalation: 42 new executables and 202 ransomware variants were identified, including Expiro, Moiva, and Ryuk.
- Blackwired observed consistent use of specific infrastructure: IP addresses, URLs, and domains that aligned with malicious intent.
- The intelligence also highlighted the download of a poisoned Fortinet operating system from an illegitimate website, which was part of the attacker’s setup.
3. Fire phase – Attack response
- On November 13, 2024, BestSeller confirmed a ransomware attack exploiting the Fortijump vulnerability.
- Blackwired restated its DTI-based containment measures, now enriched with additional threat intelligence to help limit spread and disrupt the attacker’s C2 (command-and-control) communications.
Throughout, Blackwired’s continuous zero-touch monitoring allowed it to identify the adversary’s infrastructure and actions as they evolved, and to provide actionable countermeasures that could have pre-emptively stopped and contained the attack if implemented in time.
What can organizations learn from the BestSeller case?
The BestSeller case highlights several practical lessons for organizations looking to strengthen their ransomware defenses.
1. Use early warning as a trigger for action
- Blackwired’s foresight gave BestSeller a three-week window between initial reconnaissance detection and the confirmed attack.
- During this time, Blackwired provided FastHunt DTI remediations and containment guidance that could have limited or prevented the impact.
- Key takeaway: treat early threat intelligence as a prompt for concrete action, not just as information.
2. Operationalize Direct Threat Intelligence (DTI)
- ThirdWatch DTI did more than flag generic risk; it identified specific executables, ransomware variants, IPs, URLs, and domains tied directly to the adversary.
- It also surfaced the use of a poisoned Fortinet OS and the Fortijump vulnerability, giving clear technical levers for defense teams.
- Key takeaway: build processes to quickly translate DTI into firewall rules, endpoint controls, and network blocks that can be deployed at scale.
3. Reimagine incident response as anticipatory, not reactive
- The Aim, Ready, Fire (ARFi) model shows how organizations can move from reacting to incidents to anticipating them.
- By visualizing the attacker’s infrastructure and actions as they evolve, security teams can plan containment and mitigation before the “fire” phase.
- Key takeaway: align your incident response playbooks with stages of attacker activity (reconnaissance, setup, execution) so you can intervene earlier.
4. Why this matters for leadership
- Blackwired’s intelligence gave BestSeller the opportunity to prevent or reduce considerable damage, but that required timely decision-making and execution.
- For executives, the lesson is to empower security teams to act on credible, specific threat intelligence without unnecessary delay.
In short, the BestSeller case shows how continuous, direct threat intelligence—when operationalized—can help organizations rethink how they manage ransomware risk and move toward more proactive, data-driven defense.
BestSeller Ransomware Attack
published by UPCONNECT LABS LLP
Upconnect Labs is a leading IT Managed Service Providers & IT hardware system integrator dedicated to providing comprehensive technology solutions to businesses of all sizes. With a focus on innovation, reliability, and customer satisfaction, we specialise in designing, implementing, and supporting customised IT infrastructure tailored to meet the unique needs of our clients.
Mission Statement:
At Upconnect Labs, our mission is to empower businesses with cutting-edge technology solutions that drive growth, efficiency, and success. We are committed to delivering superior customer service, fostering long-term partnerships, and exceeding expectations through continuous innovation and excellence.
Services:
- IT Infrastructure Design and Consultation:
- Comprehensive assessment of client requirements.
- Customized design and planning of IT infrastructure solutions.
- Expert consultation on hardware selection, configuration, and deployment.
- Hardware Procurement:
- Strategic partnerships with leading technology vendors.
- Procurement of high-quality hardware components at competitive prices.
- Streamlined supply chain management to ensure timely delivery.
- System Integration:
- Seamless integration of hardware components into existing IT environments.
- Configuration, testing, and optimisation of integrated systems.
- Thorough quality assurance to guarantee optimal performance and reliability.
- Network Solutions:
- Design and implementation of robust networking solutions.
- Deployment of secure wired and wireless networks.
- Network optimisation, monitoring, and management services.
- IT Infrastructure Maintenance and Support:
- Proactive maintenance to prevent downtime and minimise disruptions.
- 24/7 technical support for troubleshooting and issue resolution.
- Regular system updates, patches, and upgrades to ensure security and performance.
Clientele:
TechPro Solutions serves a diverse clientele across various industries, including:
- Corporate Enterprises
- Small and Medium-sized Businesses (SMBs)
- Educational Institutions
- Government Agencies
- Healthcare Organisations
- Non-profit Organisations
Why Choose UpConnect Labs ?
- Expertise: Our team comprises skilled professionals with extensive experience in IT infrastructure design, implementation, and support.
- Customisation: We understand that one size does not fit all. We tailor our solutions to meet the specific needs and objectives of each client.
- Reliability: We are committed to delivering reliable, high-performance technology solutions that our clients can depend on.
- Customer Service: Exceptional customer service is at the heart of everything we do. We prioritize client satisfaction and strive to exceed expectations in every interaction.