New Ransomware Operator Volcano Demon Serving Up LukaLocker
Essential information
- Published
- 03/07/2024 11:35
- Modified
- 03/07/2024 11:52
- Tags
- 2024-07-03 data theft lukalocker ransomware
- Related entities
- 3 observables, 1 intrusion sets (apt), 14 techniques (mitre), 1 malware
Description
A cybersecurity firm has encountered a new ransomware organization, dubbed Volcano Demon, responsible for recent attacks involving an encryptor called LukaLocker. The malware encrypts victims' files with the .nba extension and was successful in compromising Windows workstations and servers after harvesting administrative credentials. Prior to encryption, data was exfiltrated for double extortion techniques. The threat actors utilize phone calls with a threatening tone to extort and negotiate ransom payments.