Breaking
SecurityDeveloping Story

When the 'rescuer' is the attacker

Ransom Busters, a fake recovery firm, steals victims' ransom payments that were meant for the original criminals.

··2 hours ago·2 min read
man siting facing laptop
Photo by Clint Patterson on Unsplash

When a ransomware victim gets an unexpected email from a company offering to recover their encrypted files and delete stolen data, it might seem like a lifeline — especially if the price is far lower than the original ransom demand. But according to researchers at GuidePoint Security, one such outfit, calling itself “Ransom Busters,” is nothing more than a ransomware affiliate trying to cut its criminal partners out of the payday. The researchers assess with “moderate confidence” that the group is a single actor working across multiple ransomware-as-a-service operations, steering victims’ payments away from the legitimate ransomware operators to pocket the cash itself.

A scheme built on false promises

GuidePoint Security’s Research and Intelligence Team (GRIT) came across Ransom Busters while investigating attacks linked to DragonForce, Settra, and Anubis. The outfit emailed victims claiming it had hacked the ransomware gangs themselves and discovered their stolen data on the crooks’ servers. Ransom Busters offered to delete that data and retrieve encryption keys for a bargain-basement price of between $20,000 and $60,000.

To back up its claims, Ransom Busters demonstrated access to the same datasets held by the ransomware affiliate behind the attacks, GuidePoint said. That alone raised eyebrows, but the forensic evidence proved rather harder to explain away.

Forensic fingerprints point to one actor

GuidePoint examined two incidents in which Ransom Busters approached victims and found the intrusions shared a collection of unusually specific fingerprints. Both used SoftPerfect Network Scanner for reconnaissance, s5cmd to shovel data into AWS cloud storage, and the Remotely remote-management tool installed using PowerShell.

More damningly, the attacker created a local backdoor account using the password “Numlock!123” in both environments. The same attacker-controlled hostname, “DESKTOP-BBETH6K,” also turned up in both intrusions.

This might be explained by ransomware operators sharing tools or a prebuilt attack environment. GuidePoint said it has seen the same activity across several separate RaaS programs, however, leading it to conclude that one affiliate is likely moonlighting across multiple gangs and then cutting its employers out of the payday.

No guarantee of data deletion

GuidePoint also warned that paying the supposed rescuers provides no assurance that stolen information will actually disappear. The researchers’ advice to victims is blunt: if a mysterious stranger somehow knows you’ve been ransomwared before you’ve told anyone, and generously offers to make the whole problem disappear for $20,000, you may want to question how they got your number in the first place.

Why it matters

This scheme adds a new layer of betrayal to an already treacherous situation. For victims, it means that even after an attack, they cannot assume that anyone offering help is on their side — especially if that offer arrives unsolicited and too good to be true. The fact that a single affiliate may be operating across multiple RaaS programs also suggests that the ransomware ecosystem is not as cooperative as it might appear; even criminals are willing to undercut one another for a quick payday. This could mean that victims are now facing not only the original extortionists but also impostors who are happy to take their money and run, with no intention of actually helping. For businesses, the takeaway is clear: verify the legitimacy of any recovery offer, and never pay without confirming who you are really dealing with.

#ransomware#scam#extortion#guidepoint

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories