New Ransomware Threat Group Calls Attack Victims to Ensure Payments
ID: e2a17876-dd59-51e9-b446-3dc2378f8527
STIX ID: report--e2a17876-dd59-51e9-b446-3dc2378f8527
Feed Name: KnowBe4 Blog
Threat Score
Researchers identified a new ransomware operator called Volcano Demon that follows typical intrusion steps—harvesting admin credentials, exfiltrating data to a C2, clearing logs, and encrypting data with LukaLocker—but diverges in its extortion phase by calling leadership and IT executives directly and frequently to negotiate ransom payments, which may increase likelihood of payment; the report recommends layered email defenses and security awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
