When the 'rescuer' is the attacker
Ransom Busters, a fake recovery firm, steals victims' ransom payments that were meant for the original criminals.
When a ransomware victim gets an unexpected email from a company offering to recover their encrypted files and delete stolen data, it might seem like a lifeline — especially if the price is far lower than the original ransom demand. But according to researchers at GuidePoint Security, one such outfit, calling itself “Ransom Busters,” is nothing more than a ransomware affiliate trying to cut its criminal partners out of the payday. The researchers assess with “moderate confidence” that the group is a single actor working across multiple ransomware-as-a-service operations, steering victims’ payments away from the legitimate ransomware operators to pocket the cash itself.
A scheme built on false promises
GuidePoint Security’s Research and Intelligence Team (GRIT) came across Ransom Busters while investigating attacks linked to DragonForce, Settra, and Anubis. The outfit emailed victims claiming it had hacked the ransomware gangs themselves and discovered their stolen data on the crooks’ servers. Ransom Busters offered to delete that data and retrieve encryption keys for a bargain-basement price of between $20,000 and $60,000.
To back up its claims, Ransom Busters demonstrated access to the same datasets held by the ransomware affiliate behind the attacks, GuidePoint said. That alone raised eyebrows, but the forensic evidence proved rather harder to explain away.
Forensic fingerprints point to one actor
GuidePoint examined two incidents in which Ransom Busters approached victims and found the intrusions shared a collection of unusually specific fingerprints. Both used SoftPerfect Network Scanner for reconnaissance, s5cmd to shovel data into AWS cloud storage, and the Remotely remote-management tool installed using PowerShell.
More damningly, the attacker created a local backdoor account using the password “Numlock!123” in both environments. The same attacker-controlled hostname, “DESKTOP-BBETH6K,” also turned up in both intrusions.
This might be explained by ransomware operators sharing tools or a prebuilt attack environment. GuidePoint said it has seen the same activity across several separate RaaS programs, however, leading it to conclude that one affiliate is likely moonlighting across multiple gangs and then cutting its employers out of the payday.
No guarantee of data deletion
GuidePoint also warned that paying the supposed rescuers provides no assurance that stolen information will actually disappear. The researchers’ advice to victims is blunt: if a mysterious stranger somehow knows you’ve been ransomwared before you’ve told anyone, and generously offers to make the whole problem disappear for $20,000, you may want to question how they got your number in the first place.
Why it matters
This scheme adds a new layer of betrayal to an already treacherous situation. For victims, it means that even after an attack, they cannot assume that anyone offering help is on their side — especially if that offer arrives unsolicited and too good to be true. The fact that a single affiliate may be operating across multiple RaaS programs also suggests that the ransomware ecosystem is not as cooperative as it might appear; even criminals are willing to undercut one another for a quick payday. This could mean that victims are now facing not only the original extortionists but also impostors who are happy to take their money and run, with no intention of actually helping. For businesses, the takeaway is clear: verify the legitimacy of any recovery offer, and never pay without confirming who you are really dealing with.
Sources
- The Register Original source
Continue Reading
Grok tricked into leaking user data
A researcher found that encrypting malicious instructions lets Grok exfiltrate user chats and personal details.
JFrog Flaws Open Route to Package Cache Poisoning
Two flaws in JFrog Artifactory could let low-privileged users tamper with package metadata and compromise software supply chains.
Android Banking Trojans Gain On-Device Fraud Tools
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.