The Federal Bureau of Investigation (FBI) warns that ransomware gangs are targeting companies involved in mergers and acquisitions to make it easier to extort their victims.
In an alert published on Monday, the FBI said ransomware operators are using financial information collected before attacks as leverage to force victims to comply with ransom demands.
See also: Ransomware attack on Norsk Hydro: The culprits were arrested!

See also: BillQuick Web Suite Bug: Used to develop ransomware
Ransomware gangs target victims' stock prices
For example, last year, the REvil (Sodinokibi) ransomware gang said it was considering adding an auto-email script that would target stock exchanges, such as NASDAQ, to notify them that companies were hit by ransomware to affect their stock price.
REvil also examines stolen data after breaching company servers to find harmful information that can be used to force their victims to pay the ransom.
More recently, DarkSide ransomware announced that it would share insider information about companies traded on the NASDAQ or other stock markets with traders looking to drive down the stock price to make a quick profit.
The FBI also shared several cases where ransomware groups have used internal or public information about ongoing merger or acquisition negotiations to target vulnerable companies:
- In early 2020, a ransomware operator using the alias “Unknown” made a post on the Russian hacking forum “Exploit” that encouraged the use of the NASDAQ stock exchange to influence the extortion process. Following this post, unknown ransomware operators who negotiated a payment with a victim during a ransomware event in March 2020, stated: “We noticed that you have stocks. If you do not commit us to trading, we will leak your data to NASDAQ and see what happens to your stocks.”
- Between March and July 2020, at least three publicly traded U.S. companies actively involved in mergers and acquisitions fell victim to ransomware during their respective negotiations. Of the three pending mergers, two of the three were in private negotiations.
- A November 2020 technical analysis of Pyxie RAT, a remote access trojan that often precedes Defray777/RansomEXX ransomware infections, identified several keyword searches on the victim's network indicating interest in the victim's current and upcoming stock price.
- In April 2021, the Darkside ransomware4 hackers posted a message on their blog site to show their interest in influencing a victim's stock price.
See also: Researchers provided decryption tool to victims of BlackMatter ransomware
Paying ransoms is not encouraged
The FBI says it does not encourage paying ransoms to ransomware gangs and advises companies not to do so, as it is not guaranteed that paying will protect them from data breaches or future attacks.
Information source: bleepingcomputer.com
