logo

Cybercrooks play dress-up as 'helpful' researchers in latest ransomware ruse

ID: 39462dd5-ccda-5d67-a3e4-913c1dd4d754

STIX ID: report--39462dd5-ccda-5d67-a3e4-913c1dd4d754

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-01-10

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Arctic Wolf Labs observed two cases where ransomware victims of the Royal and Akira groups were re-extorted by a third party posing as a security researcher; the actor used anonymous Tox messaging and file.io to prove access to exfiltrated data and demanded roughly 5 BTC. Similarities across communications and tradecraft suggest the same individual or small group conducted both attempts against US-based SMBs in finance and construction, though no payments were made and attribution remains uncertain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.