Ransomware crook poses as recovery firm to steal payments from fellow extortionists
A Russian threat actor is impersonating Signal support to conduct phishing attacks targeting other ransomware groups. The goal is to steal payments intended for extortion activities, highlighting a concerning trend of organized crime leveraging social engineering tactics within the ransomware ecosystem.
This report details a sophisticated phishing campaign orchestrated by Russian threat actors. The attackers are posing as legitimate Signal support personnel, contacting other ransomware groups to request payment details for ransoms already paid. The attackers then use this information to steal the funds before the victims realize they have been defrauded. This tactic is particularly concerning as it targets the financial infrastructure of the ransomware underworld, potentially disrupting operations and impacting future attacks. The campaign demonstrates a growing trend of organized crime leveraging social engineering to exploit vulnerabilities within the ransomware community.