We’ve covered the issue of Ransomware before and how the threat has recently increased in both prevalence and sophistication. It seems that one group of criminals are fully aware of this and are using the current period of heightened interest to make threats that might not actually exist.
CloudFlare, a US company that provides content delivery networks, recently identified an email campaign by a group purporting to be the Armada Collective. For any targeted victim that is not aware of this group, some extortion emails have reportedly encouraged them to search Google for the ‘Armada Collective’ to find out more. This would quickly inform them that the group has an established reputation for online extortion rackets, having risen to prominence in November 2015 when they attacked a number of email services and several Greek banks.
Despite the email also containing the line: ‘this is not a joke’, it appears that it might well be. CloudFlare and a number of other DDoS mitigation vendors have heard from over 100 customers who received threats, but they have been unable to identify a single incident where the Armada Collective have actually launched as DDoS attack. They also noted that the group asked multiple victims to send the same ransom fee to the same Bitcoin addresses, which would make it impossible for the criminals to know which victims had paid up and which ones hadn’t.
Whether this current campaign is the genuine Armada Collective or not, they have raked in nearly £70,000 in the past two months. Our advice remains the same in that you should regularly patch your system for the latest security updates and educate your staff not to click on links without assessing whether the email is legitimate.
Backup your Data
Ensuring you have a backup of your critical information is also essential so that, should you receive a threatening extortion message, you can be confident your data is safe and you are not pressurised into paying any unnecessary ransom demands.
Your free Global Geopolitical Dashboard
PGI’s Risk Portal tool provides daily intelligence feeds, country threat assessments and analytical insights, enabling clients to track, understand and navigate geopolitical threats.
The Risk Portal gives users up-to-date information and analysis on global affairs.
The Risk Portal allows users to visualise information in a unique and instantly understandable way. Mapping filters enable the visualisation of incidents by threat category, time period, perpetrator and target type.
Risk Portal users can upgrade their accounts to include the Report Builder and Country Profile Generator features. The Report Builder allows users to select information, data and images from the Risk Portal and create bespoke reports and emails.
Subscribers to PGI’s Bespoke services receive tailored analysis on specific sectors and geographies of interest, delivered at a frequency they determine.
Subscribe to our Cyber Bytes Newsletter
Keep yourself in the loop with PGI by signing up to our Weekly Cyber Bytes email. You will receive updates, tips and narrative around what has been happening in the world of information security.