A suspected ransomware affiliate is operating under the guise of 'Ransom Busters,' a fake recovery service, contacting victims before attacks go public to steal decryption fees.

  • 'Ransom Busters' is soliciting payments between $20,000 and $60,000 from ransomware victims.
  • The group contacts victims before attacks are publicly disclosed, indicating direct involvement in the breach.
  • Evidence suggests the group is a single rogue affiliate stealing from both victims and ransomware gangs.

A sophisticated new layer of cyber extortion has emerged. GuidePoint Security's Research and Intelligence Team (GRIT) has uncovered that a suspected ransomware affiliate is masquerading as a legitimate recovery service named 'Ransom Busters.' This entity contacts victims of cyberattacks before they become public knowledge, claiming to provide decryption keys and the deletion of stolen data for a significant fee.

The Anatomy of the Deception

Ransom Busters claims to have exploited vulnerabilities in the administrative panels used by Ransomware-as-a-Service (RaaS) operations. By doing so, they allege they can access encryption keys and manage stolen data. The group has specifically targeted victims of major ransomware families, including DragonForce, Settra, and Anubis, demanding payments ranging from $20,000 to $60,000 to 'cleanse' the stolen data from hacker servers.

Why This Matters: BozokMedia Analysis

BozokMedia analysis shows that this is not a standard 'ambulance chaser' scenario. Unlike typical third-party recovery services that approach victims after an attack is publicized, Ransom Busters operates in the shadows of non-public incidents. This proximity to the initial breach suggests that the 'recovery firm' is actually an affiliate participating in the original attack, attempting to double-dip by stealing payments from both the victim and the primary ransomware gang.

This type of interference on a non-public incident is much more concerning than typical recovery scams.

Technical forensic evidence supports this theory. GRIT observed that in multiple incidents, the attackers utilized identical tools such as SoftPerfect Network Scanner and Remotely. Furthermore, they employed the same specific backdoor credentials, including the password 'Numlock!123', creating a clear digital fingerprint linking the recovery attempts to the actual ransomware activity.

Historical Background: The Evolution of Cyber Extortion

Historically, ransomware was a simple 'lock and key' transaction. However, the industry has evolved into a complex ecosystem of RaaS, where affiliates and operators share profits. The rise of 'double extortion'—where data is both encrypted and stolen—has created a vacuum for middlemen. We are now seeing the emergence of 'rogue middlemen' who exploit the distrust within these criminal networks to generate illicit revenue.

Did You Know?: Once attackers gain valid credentials, the effectiveness of traditional prevention tools drops significantly, with only about 37% of their subsequent actions being blocked.

Frequently Asked Questions

1. How can I identify if a recovery service is legitimate?
Legitimate services typically respond after an attack is public; suspicious services often contact you privately during the heat of an unannounced breach.

2. Should I pay Ransom Busters to recover my data?
Security experts strongly advise against it, as there is no guarantee of data recovery and it may simply fund further criminal activity.