Cybercriminals Court Traitorous Insiders via Ransom Notes
ID: 5349106d-311b-5317-8868-25f8a536ff5c
STIX ID: report--5349106d-311b-5317-8868-25f8a536ff5c
Feed Name: Dark Reading
Threat Score
Date Published: 2025-02-04
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
...
...
Ransomware groups have begun embedding 'advertisements' in ransom notes to recruit insiders and solicit credentials or other sensitive information, offering rewards and directing communications via Tox messenger; researchers at GroupSense observed the tactic from multiple actors including Sarcoma and a LockBit-impersonator (DoNex).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
