Volcano Demon

Threat Actor updated a month ago (2024-09-12T17:17:41.942Z)
Download STIX
Preview STIX
Volcano Demon, a recently identified threat actor, has been tracked by the researchers at Halcyon due to its unique use of locker malware known as LukaLocker. This adversary encrypts victims' files with a .nba file extension, a technique not previously seen in the cybersecurity landscape. The group primarily uses harvested administrative credentials from its victims' networks to gain access and deploy a Linux version of LukaLocker, which then locks both Windows workstations and servers. Interestingly, unlike many other similar groups, Volcano Demon does not maintain a leak site for posting stolen data. In its operations, Volcano Demon employs double extortion tactics, although it doesn't publicly disclose the stolen data. Over the past two weeks, this group has been implicated in several attacks, deploying their novel LukaLocker ransomware. The cybersecurity vendor Halcyon revealed that the group's success is largely due to the exploitation of common administrative credentials found within the victim's network. Once these are harvested, the group locks both Windows workstations and servers, demonstrating a high level of adaptability and effectiveness. Given the modus operandi of Volcano Demon, defensive measures such as multifactor authentication (MFA) and comprehensive employee training on phishing campaigns can help prevent compromises. Since the group relies heavily on exploiting administrative credentials, these measures could significantly reduce the risk of successful attacks. Furthermore, Halcyon highlighted that prior to any attack, Volcano Demon exfiltrates data to C2 services for double extortion techniques, suggesting that monitoring and securing data flow could also be an effective defense strategy.
Description last updated: 2024-09-12T17:07:47.237Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Lukalocker is a possible alias for Volcano Demon. LukaLocker is a newly discovered malware, characterized as locker ransomware, that was first identified by Halcyon researchers on June 15. The adversary behind this malicious software has been dubbed "Volcano Demon" and is responsible for several attacks within the past two weeks. LukaLocker encrypt
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Windows
Extortion
Credentials
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Volcano Demon Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
InfoSecurity-magazine
3 months ago
DARKReading
3 months ago