RANSOMWARE AFFILIATE POSES AS RECOVERY FIRM TO REDIRECT PAYMENTS
Researchers at GuidePoint Security have identified an outfit calling itself "Ransom Busters" that contacts ransomware victims before attacks become public, offering to recover encrypted files and delete stolen data for substantially less than the original extortion demand. According to GuidePoint's Research and Intelligence Team, the group is assessed with "moderate confidence" to be a ransomware affiliate operating across multiple ransomware-as-a-service operations, attempting to redirect payments away from its criminal partners. The researchers encountered Ransom Busters whilst investigating attacks linked to DragonForce, Settra and Anubis.
Ransom Busters claimed to have hacked the ransomware gangs themselves and located stolen data on their servers, offering to delete that data and provide encryption keys for between $20,000 and $60,000. The outfit demonstrated access to the same datasets held by the ransomware affiliates behind the original attacks, according to GuidePoint. Forensic evidence from two incidents showed both intrusions shared specific technical signatures: both used SoftPerfect Network Scanner for reconnaissance, s5cmd to move data to AWS cloud storage, and the Remotely remote-management tool installed via PowerShell. In both cases, the attacker created a local backdoor account using the password "Numlock!123".
The findings demonstrate a method by which criminal actors operating within ransomware networks exploit the trust issues that exist between participants in such operations. Victims contacted by Ransom Busters face exposure to further fraud, as payments to the recovery outfit would likely enrich the same affiliate behind the original attack rather than result in genuine data deletion or key recovery.