BestSeller Ransomware Attack
What does three weeks of advance warning buy you? This case study follows Blackwired's tracking of a ransomware campaign targeting BestSeller, the Danish fashion company, from the first dark web signal in October 2024 to the Fortijump exploit weeks later. See how the ThirdWatch Aim, Ready, Fire model and Direct Threat Intelligence identified adversary infrastructure early and delivered containment measures.
What happened in the BestSeller ransomware incident?
In late 2024, BestSeller, a Danish fashion company, was targeted by a ransomware campaign that Blackwired had been tracking weeks in advance.
Timeline of events:
- October 18, 2024 – Early reconnaissance: Blackwired detected suspicious activity linked to the GandCrab dark web domain. This was the reconnaissance stage and provided roughly three weeks of lead time before the confirmed attack.
- By November 8, 2024 – Infrastructure setup: Blackwired’s ThirdWatch Direct Threat Intelligence (DTI) identified a surge in malicious activity, including 42 new executables and 202 ransomware variants such as Expiro, Moiva, and Ryuk. Indicators showed consistent use of malicious IPs, URLs, and domains, including the download of a poisoned Fortinet operating system from an illegitimate site.
- November 13, 2024 – Attack confirmed: BestSeller confirmed a ransomware attack exploiting the Fortijump vulnerability. A robotic wave attack validated Blackwired’s earlier prediction.
Throughout this period, Blackwired used its Aim, Ready, Fire (ARFi) anticipatory risk model to track the adversary’s infrastructure and actions. Blackwired repeatedly provided BestSeller with DTI-based containment and remediation guidance. However, BestSeller chose not to implement the recommended FastHunt DTI remediations pre-emptively, which limited the opportunity to contain the threat before it fully materialized.
How did Blackwired detect and track the ransomware threat?
Blackwired relied on its ThirdWatch Direct Threat Intelligence (DTI) platform and the Aim, Ready, Fire (ARFi) anticipatory risk model to detect and track the threat in stages.
1. Aim phase – Early threat detection
- On October 18, 2024, Blackwired detected early reconnaissance activity tied to the GandCrab dark web domain.
- This provided about three weeks of pre-incident lead time for BestSeller to prepare and implement containment measures.
2. Ready phase – Infrastructure setup
- By November 8, 2024, ThirdWatch DTI showed a clear escalation: 42 new executables and 202 ransomware variants were identified, including Expiro, Moiva, and Ryuk.
- Blackwired observed consistent use of specific infrastructure: IP addresses, URLs, and domains that aligned with malicious intent.
- The intelligence also highlighted the download of a poisoned Fortinet operating system from an illegitimate website, which was part of the attacker’s setup.
3. Fire phase – Attack response
- On November 13, 2024, BestSeller confirmed a ransomware attack exploiting the Fortijump vulnerability.
- Blackwired restated its DTI-based containment measures, now enriched with additional threat intelligence to help limit spread and disrupt the attacker’s C2 (command-and-control) communications.
Throughout, Blackwired’s continuous zero-touch monitoring allowed it to identify the adversary’s infrastructure and actions as they evolved, and to provide actionable countermeasures that could have pre-emptively stopped and contained the attack if implemented in time.
What can organizations learn from the BestSeller case?
The BestSeller case highlights several practical lessons for organizations looking to strengthen their ransomware defenses.
1. Use early warning as a trigger for action
- Blackwired’s foresight gave BestSeller a three-week window between initial reconnaissance detection and the confirmed attack.
- During this time, Blackwired provided FastHunt DTI remediations and containment guidance that could have limited or prevented the impact.
- Key takeaway: treat early threat intelligence as a prompt for concrete action, not just as information.
2. Operationalize Direct Threat Intelligence (DTI)
- ThirdWatch DTI did more than flag generic risk; it identified specific executables, ransomware variants, IPs, URLs, and domains tied directly to the adversary.
- It also surfaced the use of a poisoned Fortinet OS and the Fortijump vulnerability, giving clear technical levers for defense teams.
- Key takeaway: build processes to quickly translate DTI into firewall rules, endpoint controls, and network blocks that can be deployed at scale.
3. Reimagine incident response as anticipatory, not reactive
- The Aim, Ready, Fire (ARFi) model shows how organizations can move from reacting to incidents to anticipating them.
- By visualizing the attacker’s infrastructure and actions as they evolve, security teams can plan containment and mitigation before the “fire” phase.
- Key takeaway: align your incident response playbooks with stages of attacker activity (reconnaissance, setup, execution) so you can intervene earlier.
4. Why this matters for leadership
- Blackwired’s intelligence gave BestSeller the opportunity to prevent or reduce considerable damage, but that required timely decision-making and execution.
- For executives, the lesson is to empower security teams to act on credible, specific threat intelligence without unnecessary delay.
In short, the BestSeller case shows how continuous, direct threat intelligence—when operationalized—can help organizations rethink how they manage ransomware risk and move toward more proactive, data-driven defense.