HomeSecurityNew ransomware group Ransomed uses a new extortion tactic

New Ransomed ransomware group uses a new extortion tactic

Life is tough when you're a newbie in the ransomware market, and the recently emerged Ransomed group seems to have learned that the hard way. However, it's learning very quickly and has begun exploiting a completely new tactic to extort its victims.

See also: DreamBus malware: Exploits a RocketMQ vulnerability to infect servers

New Ransomed ransomware group uses a new extortion tactic

The Ransomed group originally started as a forum – RansomForums – on August 15, 2023, according to Flashpoint’s research. It registered its domain and began advertising on Telegram, while also starting its own Telegram channel.

However, within a few days the site was hit by a DDoS attack – likely by another ransomware group. The perpetrators then switched to a more traditional ransomware blog pattern, where they threaten to publish their victims’ data unless a ransom is paid.

See also: FBI: International operation led to the shutdown of the Qakbot botnet

But that's what makes the Ransomed team break away from tradition.

Ransomed currently bills itself as the “Leading Company in Digital Peace Tax,” an attempt to legitimize itself as more than just an illegal enterprise. This in itself isn’t entirely new – many ransomware perpetrators consider themselves expensive pen-testers – but the methods it uses to extort are novel.

Rather than simply threatening to release data, Ransomed operators use data protection laws, such as the General Data Protection Regulation (GDPR), to convince their victims to pay up. The ransom amounts are usually much smaller than what a GDPR fine might amount to, making payment an even more desirable option.

According to its own website, the Ransomed group is minimally involved in hacking itself, instead operating as a collaborative partner program that hires other hackers to carry out the work.

According to a post on Flashpoint’s blog, “it is unclear at this time whether Ransomed is using a specific type of ransom, or is simply extorting victims through information leaks.” “Its channel initially claimed the group was looking for collaborators and has since shut down its recruitment efforts and stated that several people have joined them – there is no further information on how the group conducts attacks .”

See also: DarkGate malware activity increases

New Ransomed ransomware group uses a new extortion tactic

So far, the group's list includes just nine victims, of whom one appears to have paid, one whose details have been "removed upon request," although he may be reinstated on the list if payment is not forthcoming, and the rest either have not been paid or are in the process of paying.

The group openly discloses its location, asking potential partners to avoid attacking targets in Ukraine or Russia, as “most of the operators are from there.” Other conditions include not attacking critical infrastructure without permission and that all data must be original and not from previous leaks.

As Flashpoint points out, we are in the very early stages regarding the team, and verifying whether they have the data they claim may be difficult.

Information source: cybersecurityconnect.com.au

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS