logo

Follow-On Extortion Campaign Targeting Victims of Akira and Royal Ransomware

ID: 8b20b10a-0d58-54e6-99e6-cb4a334e779a

STIX ID: report--8b20b10a-0d58-54e6-99e6-cb4a334e779a

Feed Name: Arctic Wolf

Threat Score
65/100

Date Published: 2024-01-04

Date Updated: 2026-07-26

Author: Stefan Hostetler, Steven Campbell

...
...

Arctic Wolf Labs investigated multiple follow-on extortion incidents (Oct–Nov 2023) where actors posing as security researchers contacted organizations previously impacted by Royal and Akira ransomware, claiming access to exfiltrated data and offering to delete it for a fee. The report identifies consistent tradecraft across cases—use of Tox, file.io, low payment demands (<=5 BTC), overlapping phrasing—and concludes with moderate confidence that a single threat actor likely carried out these secondary extortion attempts, though it remains unclear whether initial ransomware groups sanctioned them.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.