The logo of Apollo Global Management is displayed on a smartphone in front of abstract background. (Photo Illustration by Timon Schneider/Getty Images)
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data.
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google.
The threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security.
The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to intercept research and steal data with national security implications.
Researchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain.
Some attackers, which researchers link to The Com, have swatted company executives to increase leverage and pressure victims to pay their ransom demands.
The company said it found more evidence of compromise across its customer base. Exposure, which has yet to be defined, poses significant downstream risk.