BestSeller Ransomware Attack
What does three weeks of advance warning buy you? This case study follows Blackwired's tracking of a ransomware campaign targeting BestSeller, the Danish fashion company, from the first dark web signal in October 2024 to the Fortijump exploit weeks later. See how the ThirdWatch Aim, Ready, Fire model and Direct Threat Intelligence identified adversary infrastructure early and delivered containment measures.
What happened in the BestSeller ransomware incident?
In late 2024, BestSeller, a Danish fashion company, was targeted by a ransomware campaign that Blackwired had been tracking weeks in advance.
Timeline of events:
- October 18, 2024 – Early reconnaissance: Blackwired detected suspicious activity linked to the GandCrab dark web domain. This was the reconnaissance stage and provided roughly three weeks of lead time before the confirmed attack.
- By November 8, 2024 – Infrastructure setup: Blackwired’s ThirdWatch Direct Threat Intelligence (DTI) identified a surge in malicious activity, including 42 new executables and 202 ransomware variants such as Expiro, Moiva, and Ryuk. Indicators showed consistent use of malicious IPs, URLs, and domains, including the download of a poisoned Fortinet operating system from an illegitimate site.
- November 13, 2024 – Attack confirmed: BestSeller confirmed a ransomware attack exploiting the Fortijump vulnerability. A robotic wave attack validated Blackwired’s earlier prediction.
Throughout this period, Blackwired used its Aim, Ready, Fire (ARFi) anticipatory risk model to track the adversary’s infrastructure and actions. Blackwired repeatedly provided BestSeller with DTI-based containment and remediation guidance. However, BestSeller chose not to implement the recommended FastHunt DTI remediations pre-emptively, which limited the opportunity to contain the threat before it fully materialized.
How did Blackwired detect and track the ransomware threat?
Blackwired relied on its ThirdWatch Direct Threat Intelligence (DTI) platform and the Aim, Ready, Fire (ARFi) anticipatory risk model to detect and track the threat in stages.
1. Aim phase – Early threat detection
- On October 18, 2024, Blackwired detected early reconnaissance activity tied to the GandCrab dark web domain.
- This provided about three weeks of pre-incident lead time for BestSeller to prepare and implement containment measures.
2. Ready phase – Infrastructure setup
- By November 8, 2024, ThirdWatch DTI showed a clear escalation: 42 new executables and 202 ransomware variants were identified, including Expiro, Moiva, and Ryuk.
- Blackwired observed consistent use of specific infrastructure: IP addresses, URLs, and domains that aligned with malicious intent.
- The intelligence also highlighted the download of a poisoned Fortinet operating system from an illegitimate website, which was part of the attacker’s setup.
3. Fire phase – Attack response
- On November 13, 2024, BestSeller confirmed a ransomware attack exploiting the Fortijump vulnerability.
- Blackwired restated its DTI-based containment measures, now enriched with additional threat intelligence to help limit spread and disrupt the attacker’s C2 (command-and-control) communications.
Throughout, Blackwired’s continuous zero-touch monitoring allowed it to identify the adversary’s infrastructure and actions as they evolved, and to provide actionable countermeasures that could have pre-emptively stopped and contained the attack if implemented in time.
What can organizations learn from the BestSeller case?
The BestSeller case highlights several practical lessons for organizations looking to strengthen their ransomware defenses.
1. Use early warning as a trigger for action
- Blackwired’s foresight gave BestSeller a three-week window between initial reconnaissance detection and the confirmed attack.
- During this time, Blackwired provided FastHunt DTI remediations and containment guidance that could have limited or prevented the impact.
- Key takeaway: treat early threat intelligence as a prompt for concrete action, not just as information.
2. Operationalize Direct Threat Intelligence (DTI)
- ThirdWatch DTI did more than flag generic risk; it identified specific executables, ransomware variants, IPs, URLs, and domains tied directly to the adversary.
- It also surfaced the use of a poisoned Fortinet OS and the Fortijump vulnerability, giving clear technical levers for defense teams.
- Key takeaway: build processes to quickly translate DTI into firewall rules, endpoint controls, and network blocks that can be deployed at scale.
3. Reimagine incident response as anticipatory, not reactive
- The Aim, Ready, Fire (ARFi) model shows how organizations can move from reacting to incidents to anticipating them.
- By visualizing the attacker’s infrastructure and actions as they evolve, security teams can plan containment and mitigation before the “fire” phase.
- Key takeaway: align your incident response playbooks with stages of attacker activity (reconnaissance, setup, execution) so you can intervene earlier.
4. Why this matters for leadership
- Blackwired’s intelligence gave BestSeller the opportunity to prevent or reduce considerable damage, but that required timely decision-making and execution.
- For executives, the lesson is to empower security teams to act on credible, specific threat intelligence without unnecessary delay.
In short, the BestSeller case shows how continuous, direct threat intelligence—when operationalized—can help organizations rethink how they manage ransomware risk and move toward more proactive, data-driven defense.
BestSeller Ransomware Attack
published by BlueTeamAssess LLC
I founded BlueTeamAssess LLC to develop and offer actionable and cost effective security solutions to SMBs.
BlueTeamAssess LLC is a veteran-owned Cybersecurity Consulting business based in Onslow County, NC.
My company wants to be the trusted advisor to small businesses for cybersecurity and related information technology needs. We will help you meet compliance requirements for HIPAA, PCI, NC cybersecurity requirements for financial advisors, and NIST 800-171 and CMMC cybersecurity requirements for providing goods and services through DOD contracts.
We help small businesses understand cybersecurity threats and their vulnerability to those threats. We offer affordable products and services to protect their business and their livelihood from those threats.
We use the SAINT Security Suite and its family of assessment products to provide cybersecurity services that assess your exposure to the many threats that can impact your business. And we help you meet compliance requirements for NIST 800-171 cybersecurity requirements for providing goods and services through DOD contracts as well as for HIPAA, PCI, the NC data breach protection law and NC cybersecurity requirements for financial advisors.
We use the CyberSecurity Assessment Tool from QS Solutions to assess the security posture of your Microsoft 365 deployment and help bring your risk score to acceptable levels through our remediation services.
We will help you reduce SPAM, secure your email and defend against ransomware. To help do this, we offer a number of solutions scalable for small business budgets and environments. These include:
- Microsoft 365 email and office software and its extensive security features and advanced threat protection.
- Fortinet security solutions that provide a Security Fabric that knits together protection for your endpoints and servers, your firewalls, your wireless network, security analytics and many other services that protect your organization technology from today’s advanced threats whether the workers are working in the office or remotely from home.
- A backup and recovery solution from Acronis to protect your critical customer and business data when the next storm or other disaster impacts your business.
You can trust BlueTeamAssess LLC be the trusted advisor to small businesses for cybersecurity and related information technology needs.