Keio Corporation Confirms Ransomware Attack Disrupting Business Systems
Keio Corporation, a major Japanese private railway operator, has confirmed a ransomware attack that disrupted some of its business systems over the weekend. While public transportation services were not affected, the incident impacted internal administrative and operational support functions. Investigations are ongoing to determine the full scope and nature of the attack.
Overview
Keio Corporation, a major private railway operator in Japan, has confirmed a ransomware attack that impacted some of its internal business systems over the weekend. While public transportation services remained operational, the incident caused disruption to administrative and operational support functions, prompting an ongoing investigation into its scope and impact.
Technical Analysis
Specific details regarding the ransomware family, initial access vector, and the exact systems compromised have not been publicly disclosed by Keio Corporation at the time of writing. Generally, ransomware attacks involve unauthorized access to a network, lateral movement, privilege escalation, and ultimately, the deployment of malware to encrypt critical files and systems. Common attack vectors include exploiting unpatched vulnerabilities, phishing campaigns, or compromised credentials, often followed by attempts to disable security software and delete backup copies to hinder recovery efforts.
Detection
- Monitor for
vssadmin.exeexecution withdelete shadowsor similar commands, indicating attempts to remove shadow copies. - Detect
wbadmin.exeexecution withdelete backupordelete catalogcommands, targeting system backups. - Look for suspicious PowerShell commands aimed at disabling security features (e.g., Windows Defender) or deleting system recovery points.
- Identify rapid, high-volume file encryption activity, often characterized by unusual file renames or the creation of new files with specific ransomware extensions (though no specific extensions are known for this incident).
- Monitor for unusual process creation from system utilities (e.g.,
cmd.exe,powershell.exe) originating from non-standard parent processes or executing atypical commands.
Sigma Detection Rules
Ransomware – VSSAdmin Shadow Copy Deletion
title: Ransomware - VSSAdmin Shadow Copy Deletion
id: 9a2e3f1b-5c7d-4e0a-8b1c-2d4f6e7a8b9c
status: experimental
description: Detects attempts by ransomware to delete shadow copies using vssadmin.exe, a common tactic to prevent system recovery.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
Image|endswith: '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'delete ShadowCopies'
condition: selection
level: critical
Ransomware – WBAdmin Backup Deletion
title: Ransomware - WBAdmin Backup Deletion
id: 7c1b5d9e-3a2f-4c8d-6e0a-1b3f5d7e9a0c
status: experimental
description: Detects attempts to delete system backups using wbadmin.exe, a common ransomware tactic.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
Image|endswith: '\wbadmin.exe'
CommandLine|contains:
- 'delete backup'
- 'delete catalog'
condition: selection
level: critical
Ransomware – PowerShell System Recovery Disablement
title: Ransomware - PowerShell System Recovery Disablement
id: 5f8a1c3e-7b9d-4e2a-0c6b-8d1f3e5a7b9c
status: experimental
description: Detects PowerShell commands commonly used by ransomware to disable system recovery features or security mechanisms. Requires PowerShell Script Block Logging.
logsource:
product: windows
service: powershell
definition: 'Script Block Logging must be enabled'
detection:
selection:
ScriptBlockText|contains:
- 'Disable-WindowsDefender'
- 'Set-MpPreference -DisableRealtimeMonitoring $true'
- 'Set-MpPreference -DisableBehaviorMonitoring $true'
- 'Set-MpPreference -DisableIOAVProtection $true'
- 'Set-MpPreference -DisableArchiveScanning $true'
- 'Set-MpPreference -MAPSReporting Disabled'
- 'Set-MpPreference -SubmitSamplesConsent NeverSend'
- 'Remove-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule" -Name "TaskCache"'
- 'Get-WmiObject -Class Win32_Shadowcopy | ForEach-Object {$_.Delete()}'
condition: selection
level: high
Mitigations
- Implement robust patch management for all operating systems, applications, and network devices, prioritizing internet-facing assets and critical infrastructure components.
- Enforce multi-factor authentication (MFA) for all remote access, administrative accounts, and critical business applications to prevent unauthorized access.
- Regularly back up critical data, ensuring backups are immutable, isolated from the production network, and regularly tested for restorability.
- Implement network segmentation to limit lateral movement within the network and contain potential breaches to specific segments.
- Conduct regular security awareness training for all employees, focusing on identifying and reporting phishing attempts and social engineering tactics.
- Deploy and maintain endpoint detection and response (EDR) solutions to monitor for suspicious activity, block malicious processes, and provide rapid incident response capabilities.
References
- https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
Generated by
gemini-2.5-flash ·1,493 input / 1,460 output tokens ·
Reviewed and approved by a human analyst before publication