Ethical Hacking News
Ransomware affiliates are becoming increasingly brazen, using tactics such as posing as recovery firms to steal payments from fellow extortionists. A new threat, dubbed "Ransom Busters," has emerged, contacting victims before their attacks become public and offering to recover encrypted files and delete stolen data for a discounted price. As researchers dig deeper, they are uncovering evidence that suggests a level of coordination and familiarity with the tools and techniques used by the ransomware gangs.
Ransomware affiliates, known as "Ransom Busters," pose as recovery firms to deceive victims.They offer to recover encrypted files and delete stolen data for a significantly reduced price than the original extortion demand.The group's modus operandi is to send emails claiming they have infiltrated ransomware gangs' servers and discovered stolen data.The "recovery" firm uses the same tools and techniques as ransomware gangs, suggesting a high level of coordination and familiarity.Ransom Busters likely moonlights across multiple gangs, attempting to cut their employers out of the payday.Paying "recovery firms" poses no assurance that stolen information would be deleted, raising significant concerns about their trustworthiness.
The cyber extortion landscape is constantly evolving, with new tactics and strategies emerging to deceive and manipulate unsuspecting victims. In a recent development that highlights the ever-widening scope of cybercrime, a group of cybercriminals posing as a recovery firm has been identified as a new threat to the ransomware community. According to researchers at GuidePoint Security, this particular affiliate, dubbed "Ransom Busters," has been making the rounds, contacting potential victims before their attacks become public, and offering to recover encrypted files and delete stolen data for a significantly reduced price than the original extortion demand.
This seemingly benevolent approach has been employed by Ransom Busters in various operations linked to the notorious ransomware-as-a-service (RaaS) groups, DragonForce, Settra, and Anubis. The outfit's modus operandi is to send emails to victims, claiming that they have infiltrated the ransomware gangs' servers and discovered the stolen data. The offer to recover the data and delete it, all for a discounted price of between $20,000 and $60,000, seems too good to be true.
However, researchers at GuidePoint Security have discovered that the story does not quite add up. An in-depth analysis of the emails and the forensic evidence collected revealed that the attackers used the same tools and techniques across multiple incidents, including SoftPerfect Network Scanner for reconnaissance, s5cmd to shovel data into AWS cloud storage, and the Remotely remote-management tool installed using PowerShell. Furthermore, the attacker created a local backdoor account using the password "Numlock!123" in both environments, which further suggests a level of coordination and familiarity with the tools and techniques used by the ransomware gangs.
GuidePoint noted that the same activity has been observed across several separate RaaS programs, leading them to conclude that one affiliate is likely moonlighting across multiple gangs and attempting to cut their employers out of the payday. This raises significant concerns about the reliability and trustworthiness of these recovery firms, as paying them would provide no assurance that stolen information would actually be deleted.
The emergence of Ransom Busters highlights the ever-evolving nature of cybercrime and the need for vigilance among potential victims. In a world where cyber extortion is on the rise, it is essential to be aware of these tactics and to exercise extreme caution when dealing with emails or messages that seem too good to be true. As the cyber landscape continues to evolve, it is crucial to stay informed and to adopt the latest security measures to protect ourselves from these types of threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Ransomware-Affiliate-Rings-in-on-the-Bandits-A-New-Threat-to-the-Cyber-extortion-Community-ehn.shtml
https://www.theregister.com/cyber-crime/2026/08/20/ransomware-crook-poses-as-recovery-firm-to-steal-payments-from-fellow-extortionists/5290344
Published: Thu Aug 20 09:54:35 2026 by llama3.2 3B Q4_K_M