Ransom Busters Claims to Hack Ransomware Servers
Ransom Busters claims it can recover ransomware data, but researchers believe the group may actually be a ransomware affiliate.
A group calling itself Ransom Busters is approaching ransomware victims with an unusual offer: pay between $20,000 and $60,000 and it claims it can recover encrypted files and remove stolen data from the servers of ransomware gangs.
There is just one problem. Security researchers don’t believe Ransom Busters is necessarily the independent recovery service it claims to be.
GuidePoint‘s Research and Intelligence Team (GRIT) says it has responded to several ransomware incidents where victims received unsolicited emails from an entity calling itself “Ransom Busters LTD.” The group claimed it had infiltrated ransomware infrastructure and found the victims’ stolen data there.
GuidePoint instead assesses with moderate confidence that Ransom Busters is a ransomware affiliate working across several ransomware-as-a-service operations and using a different approach to extort money from victims.
The emails reportedly ask victims to put the sender in contact with their CEO or IT leadership.
Ransom Busters claims to have found vulnerabilities in the administrative panels used by ransomware groups and says it has maintained access to their infrastructure for more than three years.
The group also claims it discovered the victim’s stolen files on one of those servers. For between $20,000 and $60,000, it says it can help restore access to encrypted files and delete stolen data and backups held by the ransomware operators.
Those claims have not been independently established.
What immediately caught GuidePoint’s attention was how the group knew about the attacks in the first place. The messages were sent to victims before the incidents had become publicly known.
Cybersecurity companies do sometimes contact ransomware victims to offer assistance, but GuidePoint notes that this generally happens after an attack becomes public knowledge. Ransom Busters appearing to know about an attack before that point raised obvious questions about where its information was coming from.
GuidePoint found some significant similarities while investigating two separate incidents in which Ransom Busters contacted victims.
Investigators found the same tools being used during both intrusions, including SoftPerfect Network Scanner for reconnaissance, s5cmd for transferring stolen data to AWS cloud storage and the Remotely remote monitoring and management tool, which was installed through PowerShell.
Both incidents also involved a local backdoor account using the password “Numlock!123.”
Researchers found another common detail: the same attacker-controlled hostname, “DESKTOP-BBETH6K,” appeared in both environments.
None of those details alone proves who was behind the attacks. GuidePoint noted that similar tooling could potentially result from a shared playbook or standardized environment used by multiple ransomware affiliates.
However, researchers considered that explanation less likely because they observed the same pattern across several different ransomware-as-a-service operations.
GuidePoint’s assessment is that Ransom Busters is probably not an independent security company.
Instead, researchers believe it may be a single ransomware affiliate working with multiple RaaS operations and using the Ransom Busters persona to approach victims directly.
The theory is relatively straightforward. An affiliate already involved in a ransomware attack would know exactly what data was stolen and could potentially know where that data was stored. It could then approach the victim separately and offer to “recover” or delete the information for another payment.
In other words, the same criminals who helped create the problem could potentially be offering to solve it.
GuidePoint says the activity was observed in incidents involving ransomware groups including DragonForce, Settra and Anubis.
For victims, the biggest concern is that there is no reliable way to know whether paying Ransom Busters would actually result in stolen information being deleted.
Even when criminals claim to have removed data, victims have no simple way to verify that every copy has disappeared. GuidePoint warns that paying a criminal party provides no guarantee that stolen information will be deleted or that encrypted files will be recovered.
Ransom Busters reportedly gave an unusual explanation for its fees when questioned about why it wasn’t providing the service for free. The group claimed that working without compensation could put its access to ransomware infrastructure at risk.
GuidePoint found that explanation difficult to accept.
The Ransom Busters activity shows how ransomware attacks can continue creating problems even after the initial intrusion.
A company that has just been encrypted and had its data stolen is already under enormous pressure. An unsolicited message claiming to have a way out could therefore be very convincing, particularly when the sender appears to know details about the attack that have not been made public.
But according to GuidePoint, that apparent inside knowledge may be exactly what makes the operation suspicious.
Rather than being a group fighting ransomware criminals, Ransom Busters may simply be another criminal actor trying to take a cut from the same victims.
For organizations dealing with ransomware, the lesson is fairly simple: an unexpected offer to “rescue” your data deserves just as much scrutiny as the original ransom demand.
Sources: Hacker News and GuidePoint Security
Related articles :
__Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.__