Ransomware actors are utilizing a previously unseen tactic in their ransomware notes: posting advertisements to solicit insider information.
Researchers at the GroupSense threat intelligence team shared their findings with Dark Reading, including screenshots of the strategies these gangs are using. Groups including Sarcoma and another syndicate believed to be impersonating LockBit ransomware, known as DoNex, have adopted the strategy, the firm noted.
Part of one ransomware note includes the usual details stating that the company is in critical condition, its backups destroyed, and databases exported. Farther down in the message, however, the group states: "If you help us find this company's dirty laundry you will be rewarded. You can tell your friends about us. If you or your friend hates his boss, write to us and we will make him cry and the real hero will get a reward from us."
[...]
Cybercriminals Court Traitorous Insiders via Ransom Notes
Cybercriminals Court Traitorous Insiders via Ransom Notes
-
- Secretary
- Posts: 335
- Joined: Mon Oct 30, 2023 1:32 am
- Location: Vicksburg, MS
- ISC2 Member Status: Yes
- Contact:
Cybercriminals Court Traitorous Insiders via Ransom Notes
Robert B. Carleton + ISC2 Central Mississippi Secretary