In a worrying new trend, malicious actors – such as the Midnight hacking group – are targeting American organizations with fake ransomware threats to extort money – despite having no actual data or files to leak!
In recent years, fraudulent extortionists have been exploiting data breaches and ransomware incidents to extort money from unsuspecting American businesses, threatening to publish or sell their stolen information if they don't pay.
Sometimes, attackers add an extra layer of pressure by threatening a denial-of-service (DDoS) attack if their demands are not followed.
See also: Sun Pharmaceuticals: Confirmed ransomware attack
Threatening factors
Since March 16, malicious actors known as “Midnight” have targeted organizations in the United States.
In their messages, they not only imitate ransomware and data extortion gangs, but also falsely assume the role of attackers, stealing hundreds of gigabytes of valuable information.
In a single email sent to a staff member of a petroleum additive company, the attacker identified themselves as Silent Ransom Group (SRG) – a splinter faction of the Conti that aims to steal sensitive data and blackmail their victim named Luna Moth.
In December 2021, a malicious actor under the alias Surtr ransomware group emerged and developed a reputation for encrypting corporate networks. The same message used in the subject line was associated with this threat.

In an email, Midnight Group claimed responsibility for the breach of 600GB of data from servers and described it as “key data.”
It had been more than six months since a senior financial planner left the target company, but messages were still being delivered to his address.

Pending DDoS threat
A report in late March from the managed detection and response division at corporate research and risk consulting firm Kroll notes that some senders of similar emails also threatened DDoS attacks.
From March 23rd onwards, Kroll researchers noticed an increase in reports of emails sent by the Silent Ransom group.
According to Kroll correspondents, there has been a recent surge in scams using the names of well-known cybercriminals in an attempt to instill fear while providing credibility. This “new wave” is designed as a means of intimidation.
Kroll has witnessed such incidents since 2021, however the first signs of this activity began to appear in early November 2019. Even those who had not paid were affected by these DDoS attacks.
See also: Money Message: The new ransomware that demands millions in ransom
However, the attacks were relatively simple DDoS attacks and were accompanied by a warning that more serious attacks would follow unless their ransom demands were met.
The activity in these incidents resembles that of a ransomware group in 2017, which sent DDoS threats to thousands of companies under the guise of notorious hacking groups such as New World Hackers, Lizard Squad, LulzSec, Fancy Bear , and Anonymous.

Targeting victims of ransomware attacks
A report from Arete, a leading incident response firm, further supports Kroll’s findings about the Midnight Group’s deceptive emails that mirror Surtr and SRG. It also noted an exponential increase in fake emails sent before March 24.
After investigating the situation, incident responders determined that Midnight had targeted institutions that were former ransomware victims.
Arete analysts identified the original perpetrators as QuantumLocker (now known as DagonLocker), Black Basta, and Luna Moth.
According to Arete, at least 15 of its past and current customers have experienced false threats from Midnight Group – then reinforced these claims of data theft with vague details.
See also: DISH: Multiple lawsuits after ransomware attack
It is puzzling how the victims are identified - however, it seems likely that the selections could be made from publicly accessible data leak websites, news articles, social media , or corporate disclosures.
However, Arete noticed that the fake attacker managed to identify some ransomware victims even when there was no public record of the attack – a possible sign that he had collaborated with the original hackers.
Despite receiving payments, ransomware perpetrators often continue to trade and market the data stolen from their victims. By delving into these marketplaces and forums where this activity takes place, Midnight Group could quickly identify previously undisclosed cyberattack targets.

Midnight's blackmail plan
The Midnight Group's extortion scheme is not new at all. In 2019, ransomware incident response firm Coveware spotted it and dubbed it Phantom Incident Extortion.
According to Coveware, the threat actor attempts to add legitimacy and urgency by using data specifically tailored for their target. They then emphasize a costly outcome if payment is not received quickly, while demanding a much smaller amount than would be required in the event of a public exposure.
All three of these elements are the mainstays of a phantom incident extortion (PIE) and a clear indication of a threat void.
Coveware recently released an updated report that now includes a sample email from the Midnight group, in addition to four examples of PIE scams.
All three companies believe the Midnight Group threats are part of a fraud campaign. Arete's attempt to interact with the threat actor did not result in any response or evidence of stolen data from the hacker.
To protect yourself from a potential malicious attack, it is recommended that you carefully evaluate such emails to identify the elements of a fake extortion message and dismiss them as a meaningless threat.
Information source: bleepingcomputer.com
