logo

New Ransomware Threat Group Calls Attack Victims to Ensure Payments

ID: e2a17876-dd59-51e9-b446-3dc2378f8527

STIX ID: report--e2a17876-dd59-51e9-b446-3dc2378f8527

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2024-07-17

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Researchers identified a new ransomware operator called Volcano Demon that follows typical intrusion steps—harvesting admin credentials, exfiltrating data to a C2, clearing logs, and encrypting data with LukaLocker—but diverges in its extortion phase by calling leadership and IT executives directly and frequently to negotiate ransom payments, which may increase likelihood of payment; the report recommends layered email defenses and security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.