A sophisticated cybercriminal is posing as a recovery service named 'Ransom Busters' to scam ransomware victims. By contacting victims before attacks are public, the group reveals its true identity as a rogue affiliate seeking double payments.
- A suspected ransomware affiliate is masquerading as 'Ransom Busters,' a fake recovery firm.
- The group contacts victims privately before attacks are publicly disclosed, indicating insider knowledge.
- They demand between $20,000 and $60,000 to 'delete' stolen data and provide decryption keys.
In a disturbing evolution of cyber extortion, a rogue ransomware affiliate is reportedly operating under the guise of a legitimate recovery service named 'Ransom Busters.' According to findings by GuidePoint Security's Research and Intelligence Team (GRIT), this group is proactively contacting ransomware victims, claiming they can provide decryption keys and ensure the deletion of stolen data for a significant fee.
The most alarming aspect of this scheme is the timing. Unlike traditional 'ambulance chasers' who contact victims after an attack has been publicized, Ransom Busters reaches out to victims while the breach is still confidential. This level of intelligence strongly suggests that the entity is not a third-party recovery firm, but the very attacker responsible for the initial breach.
Why This Matters
BozokMedia analysis shows that this shift toward 'double extortion' tactics creates a chaotic environment for incident responders. When a rogue affiliate attempts to intercept payments, it undermines the negotiation process and increases the likelihood that data will be leaked regardless of any payment made to the purported recovery service.
This type of interference on a non-public incident is much more concerning as it indicates direct involvement of the attacker.
Technical forensic evidence supports the suspicion. GRIT identified that in multiple incidents, the attackers utilized identical tools such as SoftPerfect Network Scanner and s5cmd. Furthermore, they employed the same specific backdoor credentials, including the password 'Numlock!123' and a consistent hostname 'DESKTOP-BBETH6K', linking 'Ransom Busters' directly to known ransomware-as-a-service (RaaS) operations.
The group has specifically targeted data stolen from major ransomware gangs like DragonForce, Settra, and Anubis. They offer to 'cleanse' the stolen data from these servers for fees ranging from $20,000 to $60,000. However, security experts warn that paying such entities offers no guarantee of data destruction.
Coveware, a leading ransomware negotiation firm, has also confirmed encountering similar 'middlemen.' Elizabeth Cookson, Senior Director of IR at Coveware, noted that this behavior is distinct from typical recovery scammers. The increased distrust within RaaS ecosystems is likely driving affiliates to seek unauthorized profits outside of their standard revenue-sharing agreements with gang operators.
Frequently Asked Questions
1. How can I identify a fake ransomware recovery service?
Be extremely wary of any service that contacts you privately before your breach is public knowledge or makes claims about having access to the attackers' internal servers.
2. Should I pay 'Ransom Busters' to delete my data?
No. Security experts and intelligence teams strongly advise against paying these rogue affiliates, as there is no evidence they actually fulfill their promises.