logo

Cybercriminals Court Traitorous Insiders via Ransom Notes

ID: 5349106d-311b-5317-8868-25f8a536ff5c

STIX ID: report--5349106d-311b-5317-8868-25f8a536ff5c

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-02-04

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Ransomware groups have begun embedding 'advertisements' in ransom notes to recruit insiders and solicit credentials or other sensitive information, offering rewards and directing communications via Tox messenger; researchers at GroupSense observed the tactic from multiple actors including Sarcoma and a LockBit-impersonator (DoNex).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.