HomeSecurityTommyLeaks and SchoolBoys ransomware: Are they the same group?

TommyLeaks and SchoolBoys ransomware: Are they the same group?

TommyLeaks and SchoolBoys are both ransomware gangs that have caused a lot of damage in the past year. However, it seems that the two gangs are the same threat actor.

See also: METRO: Its IT systems are out of service after a cyberattack

TommyLeaks

Last month, a security researcher from MalwareHunterTeam tweeted that a new threat group called “TommyLeaks” had emerged.

See also: GitHub: Repositories with fake PoC exploits distribute malware

This hacking group breaches corporate network security, steals data, and attempts to extort ransom from its victims to prevent the data it has stolen from being made public . The ransom amounts requested by this group range from $400,000 to $700,000.

TommyLeaks and SchoolBoys ransomware: Are they the same group?

In October, MalwareHunterTeam discovered another new ransomware group called 'SchoolBoys Ransomware Gang' that claims to remove data and encrypt machines during its attacks.

See also: Google Play: Android adware apps have over 20 million downloads

TommyLeaks and SchoolBoys ransomware: Are they the same group?

Bleepingcomputer found a sample of the cryptographer created using the leaked LockBit 3.0 builder.

TommyLeaks

The attackers steal data during their attacks, but they currently do not have a publicly accessible data leak website.

While at the time, there was nothing connecting the two groups, both were using Tor chat for their trading sites.

TommyLeaks SchoolBoys

The strangest thing is that the same chat system has only been used by the Karakurt team.

Is this actually the same team?

This week, after investigation, BleepingComputer revealed that the TommyLeaks group and the SchoolBoys Ransomware gang are the same threat actor.

In a SchoolBoys group negotiation chat shared with BleepingComputer, the hackers greet their victim as “TommyLeaks” in their attempts to force him to pay the ransom.

While it is unclear why they are using two different names as part of their business, they may be trying to implement the approach of the Conti and Karakurt.

AdvIntel CEO Vitali Kremez told BleepingComputer earlier this year that the Karakurt group was a member of the Conti cybercrime syndicate.

If Conti's ransomware encryptor is blocked during an attack, the hackers then threaten to release the stolen data unless they are paid – but using the Karakurt brand instead of Conti.

We don't know for sure yet, but it appears that the TommyLeaks/SchoolBoys group is targeting entities of all sizes. This is a type of organization that businesses should be aware of and watch out for.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS