HIGHransomware·

Keio Corporation Confirms Ransomware Attack Disrupting Business Systems

Keio Corporation, a major Japanese private railway operator, has confirmed a ransomware attack that disrupted some of its business systems over the weekend. While public transportation services were not affected, the incident impacted internal administrative and operational support functions. Investigations are ongoing to determine the full scope and nature of the attack.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

Keio Corporation, a major private railway operator in Japan, has confirmed a ransomware attack that impacted some of its internal business systems over the weekend. While public transportation services remained operational, the incident caused disruption to administrative and operational support functions, prompting an ongoing investigation into its scope and impact.

Technical Analysis

Specific details regarding the ransomware family, initial access vector, and the exact systems compromised have not been publicly disclosed by Keio Corporation at the time of writing. Generally, ransomware attacks involve unauthorized access to a network, lateral movement, privilege escalation, and ultimately, the deployment of malware to encrypt critical files and systems. Common attack vectors include exploiting unpatched vulnerabilities, phishing campaigns, or compromised credentials, often followed by attempts to disable security software and delete backup copies to hinder recovery efforts.

Detection

  • Monitor for vssadmin.exe execution with delete shadows or similar commands, indicating attempts to remove shadow copies.
  • Detect wbadmin.exe execution with delete backup or delete catalog commands, targeting system backups.
  • Look for suspicious PowerShell commands aimed at disabling security features (e.g., Windows Defender) or deleting system recovery points.
  • Identify rapid, high-volume file encryption activity, often characterized by unusual file renames or the creation of new files with specific ransomware extensions (though no specific extensions are known for this incident).
  • Monitor for unusual process creation from system utilities (e.g., cmd.exe, powershell.exe) originating from non-standard parent processes or executing atypical commands.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Ransomware – VSSAdmin Shadow Copy Deletion

title: Ransomware - VSSAdmin Shadow Copy Deletion
id: 9a2e3f1b-5c7d-4e0a-8b1c-2d4f6e7a8b9c
status: experimental
description: Detects attempts by ransomware to delete shadow copies using vssadmin.exe, a common tactic to prevent system recovery.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 1
    Image|endswith: '\vssadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'delete ShadowCopies'
  condition: selection
level: critical

Ransomware – WBAdmin Backup Deletion

title: Ransomware - WBAdmin Backup Deletion
id: 7c1b5d9e-3a2f-4c8d-6e0a-1b3f5d7e9a0c
status: experimental
description: Detects attempts to delete system backups using wbadmin.exe, a common ransomware tactic.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 1
    Image|endswith: '\wbadmin.exe'
    CommandLine|contains:
      - 'delete backup'
      - 'delete catalog'
  condition: selection
level: critical

Ransomware – PowerShell System Recovery Disablement

title: Ransomware - PowerShell System Recovery Disablement
id: 5f8a1c3e-7b9d-4e2a-0c6b-8d1f3e5a7b9c
status: experimental
description: Detects PowerShell commands commonly used by ransomware to disable system recovery features or security mechanisms. Requires PowerShell Script Block Logging.
logsource:
  product: windows
  service: powershell
  definition: 'Script Block Logging must be enabled'
detection:
  selection:
    ScriptBlockText|contains:
      - 'Disable-WindowsDefender'
      - 'Set-MpPreference -DisableRealtimeMonitoring $true'
      - 'Set-MpPreference -DisableBehaviorMonitoring $true'
      - 'Set-MpPreference -DisableIOAVProtection $true'
      - 'Set-MpPreference -DisableArchiveScanning $true'
      - 'Set-MpPreference -MAPSReporting Disabled'
      - 'Set-MpPreference -SubmitSamplesConsent NeverSend'
      - 'Remove-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule" -Name "TaskCache"'
      - 'Get-WmiObject -Class Win32_Shadowcopy | ForEach-Object {$_.Delete()}'
  condition: selection
level: high

Mitigations

  1. Implement robust patch management for all operating systems, applications, and network devices, prioritizing internet-facing assets and critical infrastructure components.
  2. Enforce multi-factor authentication (MFA) for all remote access, administrative accounts, and critical business applications to prevent unauthorized access.
  3. Regularly back up critical data, ensuring backups are immutable, isolated from the production network, and regularly tested for restorability.
  4. Implement network segmentation to limit lateral movement within the network and contain potential breaches to specific segments.
  5. Conduct regular security awareness training for all employees, focusing on identifying and reporting phishing attempts and social engineering tactics.
  6. Deploy and maintain endpoint detection and response (EDR) solutions to monitor for suspicious activity, block malicious processes, and provide rapid incident response capabilities.

References

  • https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

  • T1486 — Data Encrypted for Impact
  • T1490 — Inhibit System Recovery
  • T1070.004 — File Deletion
🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,493 input / 1,460 output tokens ·
Reviewed and approved by a human analyst before publication
#ransomware#critical-infrastructure#data-encryption#high#japan#ransomware