Skip to content
Tech News
← Back to articles

Rogue ransomware affiliate poses as data recovery firm to steal payments

read original more articles
Why This Matters

This incident highlights the evolving tactics of ransomware affiliates who are now impersonating legitimate recovery services to scam victims and steal payments. It underscores the importance for organizations and consumers to remain vigilant against sophisticated social engineering and fraud schemes in the cybersecurity landscape. Recognizing these scams can prevent financial losses and help maintain trust in cybersecurity responses.

Key Takeaways

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting victims before the attacks become public and claiming it can provide decryption keys and delete stolen data for a fee.

GuidePoint Security's Research and Intelligence Team (GRIT) disclosed this activity after responding to several recent ransomware attacks in which victims received emails from Ransom Busters offering to help recover from the attack.

The messages were suspicious because they were sent to victims before the attacks became public, raising questions about how they knew about the cyberattacks in the first place.

Ransom Busters claimed it exploited vulnerabilities in administrative panels used by ransomware-as-a-service (RaaS) operations, giving it access to encryption keys and data stolen from victims.

The group offered to delete the stolen data from ransomware servers, including those belonging to DragonForce, Settra, and Anubis, for between $20,000 and $60,000.

However, evidence from two incidents leads GRIT to believe Ransom Busters is likely not a true recovery firm, but the ransomware affiliate responsible for the attacks.

In both cases, the attackers used the same software, including SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. They also utilized the same tactics, including creating a local backdoor account using the password 'Numlock!123' and the same attacker-controlled hostname, 'DESKTOP-BBETH6K'.

GRIT says it observed overlapping activity across multiple RaaS operations and believes, with moderate confidence, that Ransom Busters is a single ransomware affiliate using its access to steal ransom payments from the ransomware gangs it works with.

GRIT told BleepingComputer that it has not seen any victims pay Ransom Busters and discourages victims from doing so. However, in one incident involving Ransom Busters, the victim instead paid the RaaS operation behind the attack.

The researchers say the victim's name and stolen data were not published on the ransomware operation's data leak site, and they found no evidence that Ransom Busters leaked the stolen data outside the RaaS environment.

... continue reading