Ransomware gang copycatted victim’s website to leak stolen data

The ALPHV ransomware drivers have gotten imaginative with their a rip-off strategy and, in no less than one case, made an imitation of the victims's highlight distribute taken information on it.

Image by storyset on Freepik

Apparently ALPHV, otherwise called BlackCat ransomware, is known for testing new a scam strategies as a method for squeezing and sully their victims into paying.

While these strategies may not find success, they present an always adding inconvenience geology that victims  need to explore.

Programmers make taken information more straightforward to get

On December 26, the danger entertainer distributed on their information spill site concealed on the Pinnacle network that they had compromised an organization in monetary administrations.


As the victims didn't satisfy the difficulty entertainer's needs, BlackCat distributed every one of the taken records as a punishment a standard step for ransomware administrators.


As a divagation from the typical cycle, the programmers chose to likewise bungle the information on a point that imitates the victims's the extent to which the appearance and the circle name go.

The programmers didn't keep the first titles of the point. They utilized their own titles to sort out the shouted information.


The cloned webpage is on the unmistakable web to guarantee the wide accessibility of the taken records. It as of now shows bright reports, from updates to staff, installment structures, hand word, information on means and charges, financial information for mates, and visa audits.

Altogether, there are3.5 GB of records. ALPHV likewise shared the taken information on a train-sharing help that permits mysterious transferring and dispersed the connection on its break point.


Recent fad framing

 Brett Puerile, inconvenience pundit at network protection organisation Emsisoft, said that sharing the information on a typo squatted circle would be a greater worry to the victims organization than dispersing the information through a site on the Peak organization, which is known principally by the infosec local area.

"I wouldn't be at all shocked assuming Alphv had attempted to weaponize the company's visitors by guiding them toward that site " Brett Puerile

This strategy could address the send off of a recent fad that might be embraced by other ransomware packs, particularly since the costs to do it are not even close to critical.

Previous Post Next Post