Cybercrooks play dress-up as 'helpful' researchers in latest ransomware ruse
ID: 39462dd5-ccda-5d67-a3e4-913c1dd4d754
STIX ID: report--39462dd5-ccda-5d67-a3e4-913c1dd4d754
Feed Name: The Register (Security)
Arctic Wolf Labs observed two cases where ransomware victims of the Royal and Akira groups were re-extorted by a third party posing as a security researcher; the actor used anonymous Tox messaging and file.io to prove access to exfiltrated data and demanded roughly 5 BTC. Similarities across communications and tradecraft suggest the same individual or small group conducted both attempts against US-based SMBs in finance and construction, though no payments were made and attribution remains uncertain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
