A hacking group, called Volcano Demon, is distributing a new ransomware (LukaLocker) but is not using a data. Instead, the hackers are calling key executives at the victim organizations to threaten and pressure them.

Cybersecurity vendor Halcyon has claimed that the “Volcano Demon” group has carried out several attacks in the past fortnight, deploying the LukaLocker ransomware variant. The ransomware encrypts files, adding the .nba extension. The group appears to have gone to great lengths to ensure it evades detection and analysis.
See also: Brain Cipher apologizes for ransomware attack in Indonesia
“The ransomware is an x64 PE binary written in C++,” the report explains. “The LukaLocker ransomware uses API obfuscation and dynamic API resolution to hide its malicious functionality – evading detection, analysis, and reverse engineering”.
Upon execution, the ransomware terminates various services and processes ontarget systems, including backup and endpoint detection, AV, system monitoring, and remote access.
Halcyon researchers have observed that hackers can lock down both Windows workstations and servers, and steal data to blackmail victims.
However, what makes the LukaLocker ransomware more special is that the Volcano Demon hackers don't have a data-leakage website to blackmail victims. They call executives of the victim companies to pressure them to pay a ransom.
"The calls are from unknown numbers and may be threatening," Halcyon warned.
See also: Heritage Valley Health System fined $950,000 for Ransomware attack

The ransom note is also threatening: “Your corporate network has been encrypted. And that’s not all – we have studied and downloaded a lot of your data… If you ignore this incident, we will ensure that your confidential data will become widely available to the public. We will ensure that your customers and partners will find out everything and the attacks will continue. Some of the data will be sold to scammers who will attack your customers and employees.”
New tactics require a change in approach
Adam Pilton, senior cybersecurity at CyberSmart, said that phone extortion is complicating efforts to tackle ransomware incidents.
“With a phone call coming from an unknown number, the number of variables increases, which means you may need a negotiator on standby and available at all times,” he argued. “This increases the cost of the negotiation service. It also means the negotiator needs to be prepared for all eventualities.”
However, there could also be new evidence for law enforcement. "The phone data may be hidden, but the information the attacker is giving away is potentially much more. There will be voice data and possible background noise, as well as records log call."
See also: BlackSuit ransomware: Responsible for the attack on KADOKAWA
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ransomware attacks can have a devastating impact on businesses, with the potential to disrupt operations, cause financial loss, and damage a company's reputation. In addition to the immediate consequences of paying the ransom or losing sensitive data, companies may also face legal consequences for failing to protect customer or employee information.
As the ransomware threat continues to grow and evolve, it is more important than ever for organizations to implement strong cybersecurity measures. This includes regularly backing up data , implementing strong security protocols, and staying informed about emerging threats.
Source: www.infosecurity-magazine.com
