A new cyber threat actor known as Ransom Busters is proactively targeting ransomware victims, offering to delete stolen data from criminal servers for a steep fee.

  • Ransom Busters is contacting victims directly via email.
  • The group offers to 'wipe' stolen data for fees between $20,000 and $60,000.
  • Security analysts warn this is a highly anomalous and suspicious activity.

A new and highly irregular player has entered the cybercrime landscape. A group identifying itself as Ransom Busters has claimed to possess the capability to hack into the very servers used by ransomware gangs. Rather than launching traditional attacks, they are positioning themselves as a bizarre 'cleanup service' for organizations already reeling from data breaches.

According to recent intelligence, the group is proactively reaching out to victimized organizations. They offer a deceptive service: for a fee ranging from $20,000 to $60,000, they claim they will access the ransomware groups' servers and permanently delete the stolen sensitive data, effectively preventing its leak or sale on the dark web.

Why This Matters

BozokMedia analysis shows that this development represents a terrifying evolution in the cybercrime ecosystem. We are witnessing the emergence of a 'predatory intermediary' model. This complicates the incident response process for companies, as they must now determine if this new entity is a legitimate security actor or simply another layer of extortion designed to exploit an already compromised situation.

"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," stated GuidePoint Research.

The skepticism among cybersecurity professionals is high. Many believe that Ransom Busters may not actually have any control over the stolen data. Instead, they may be engaging in a sophisticated form of social engineering, targeting the desperation of companies to avoid a public data leak by demanding a second ransom.

Historical Background

The evolution of ransomware has moved from simple file encryption to complex 'Double Extortion' tactics, where data is both encrypted and stolen. The emergence of actors claiming to 'counter-hack' these criminals adds a third layer of complexity to an already volatile landscape, mirroring the chaotic nature of the dark web economy.

Did You Know?: In many ransomware attacks, the attackers sell access to the victim's network to other criminals, creating a chain of multiple different threat actors.

Frequently Asked Questions

1. Is Ransom Busters a legitimate security company?
No. Their methods involve unauthorized access and extortion, placing them firmly in the category of cybercriminals.

2. Should companies pay them to secure their data?
Security experts strongly advise against it, as payment provides no guarantee and often marks the organization as a 'soft target' for future extortion.