Ransomware crook poses as recovery firm to steal payments from fellow extortionists

Summary

A ransomware operator has been impersonating a data recovery firm to trick other ransomware extortionists into paying them to decrypt stolen data. This tactic highlights a lack of trust within the ransomware ecosystem, where even criminals are susceptible to scams.

IFF Assessment

FOE

This demonstrates a new tactic by threat actors to exploit even their own kind, indicating increasing sophistication and deception within the criminal underground.

Defender Context

This incident reveals internal conflict and evolving deception tactics within ransomware operations, suggesting that defenders should monitor for novel social engineering schemes targeting both victims and other threat actors. Understanding these internal dynamics can provide intelligence on threat actor motivations and methods.

Read Full Story →