New ransomware group uses phone calls to pressure victims, researchers say

Avatar

Researchers say they have discovered a new ransomware group named Volcano Demon that has carried out at least two successful attacks in the past two weeks.

The group’s targets were companies in the manufacturing and logistics industries, said Tim West, an analyst at the cybersecurity firm Halcyon, in a comment to Recorded Future News. He declined to provide further information about the targets.

What’s interesting about this ransomware group, Halcyon researchers said, is that it has no public leaks website but instead uses phone calls to intimidate and negotiate payments with leadership at victim organizations. These calls originate from unidentified numbers and often carry a threatening tone, the researchers said.

Before calling, the hackers encrypted files on the victims’ systems with previously unknown LukaLocker ransomware and left a ransom note:

“If you ignore this incident…we will make sure that your clients and partners know about everything, and attacks will continue. Some of the data will be sold to scammers who will attack your clients and employees,” the note reads.

Volcano Demon successfully locked Windows workstations and servers by exploiting common administrative credentials obtained from the network, Halcyon said.

The group used a double extortion technique to maximize the chances of receiving payment, Halcyon said. Prior to the LukaLocker infection, they exfiltrated victims’ data to command-and-control (C2) services and only then encrypted it.

Tracking this threat actor was challenging, researchers said. The attackers cleared log files on targeted machines  before exploitation, “making a comprehensive forensic evaluation nearly impossible.” 

West told Recorded Future News that the hackers spoke “with a heavy accent” but it was too difficult to tell their origin without recordings, which aren’t available to date.

“They call very frequently, almost daily in some cases,” he said, adding that the company cannot share the specifics of the exchange between the hackers and the victims.

It is not yet clear if Volcano Demon operates independently or is an affiliate of a known ransomware group. West said that for now, Halcyon has not been able to identify such links.

Ransomware operators continue to evolve, with several new threat actors recently emerging and targeting a diverse range of industries, according to Halcyon.

In May 2024, researchers discovered a criminal gang named Arcus Media, which operates a ransomware-as-a-service model, allowing other threat actors to use their malware. Over the past month, the hackers reportedly targeted victims in the U.S., the U.K., India and Brazil.

Another group, Space Bears, surfaced earlier in April, “quickly gaining notoriety for their corporate-themed data leak site and strategic affiliations,” including with the Phobos ransomware-as-a-service group.

The analysis of these groups’ activities suggests that they “may be more organized and funded than previously anticipated,” researchers said.

CybercrimeNews
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

Cobalt Strike: International law enforcement operation tackles illegal uses of ‘Swiss army knife’ pentesting tool

Next Post

Cobalt Strike: International law enforcement operation tackles illegal uses of ‘Swiss army knife’ pentesting tool

Related Posts

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems

Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities. The packages in question are listed below - node-telegram-utils (132 downloads) node-telegram-bots-api (82 downloads) node-telegram-util (73 downloads) According to supply chain
Avatar
Read More

Microsoft Exposes LLMjacking Cybercriminals Behind Azure AI Abuse Scheme

Microsoft on Thursday unmasked four of the individuals that it said were behind an Azure Abuse Enterprise scheme that involves leveraging unauthorized access to generative artificial intelligence (GenAI) services in order to produce offensive and harmful content. The campaign, called LLMjacking, has targeted various AI offerings, including Microsoft's Azure OpenAI Service. The tech giant is
Avatar
Read More

Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business

AI agents are changing the way businesses work. They can answer questions, automate tasks, and create better user experiences. But with this power comes new risks — like data leaks, identity theft, and malicious misuse. If your company is exploring or already using AI agents, you need to ask: Are they secure? AI agents work with sensitive data and make real-time decisions. If they’re not
Avatar
Read More