logo

Extortion Campaign Targeting Victims of Akira, Royal Ransomware

ID: cf96a330-029a-5a7a-bd5e-34ba3bde746b

STIX ID: report--cf96a330-029a-5a7a-bd5e-34ba3bde746b

Feed Name: Arctic Wolf Blog

Threat Score
65/100

Date Published: 2024-01-04

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs documents multiple follow-on extortion incidents (Oct–Nov 2023) in which actors claiming to be security researchers contacted prior Royal and Akira ransomware victims, asserted access to exfiltrated data, and offered to delete or return it for a small fee; stylistic and behavioral overlaps (communication via Tox, use of file.io, low payment demands, overlapping phrases) lead analysts to conclude with moderate confidence a common actor conducted these campaigns, though links to the original ransomware groups remain unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.