Bogus rescue outfit double-dips on ransomware victims

GuidePoint finds a sham firm called Ransom Busters billing victims for recoveries it likely cannot deliver.

CSBadmin
2 Min Read

GuidePoint Security’s research arm, GRIT, has uncovered a scam that preys on ransomware victims a second time. An outfit calling itself Ransom Busters contacts companies whose attacks have not yet been made public, offering to delete stolen data and retrieve encryption keys for between $20,000 and $60,000.

The twist is that Ransom Busters is not a band of white-hat rescuers. GuidePoint assesses with moderate confidence that it is a ransomware affiliate working across several ransomware-as-a-service operations, steering payments away from its own criminal partners. The outfit emailed victims claiming it had hacked the gangs and found their stolen data, and it demonstrated access to the same datasets held by the attackers.

Forensics made the connection harder to explain away. In two incidents, the intrusions shared unusual fingerprints: SoftPerfect Network Scanner for reconnaissance, s5cmd for moving data into AWS cloud storage, the Remotely management tool installed via PowerShell, a local backdoor account with the password Numlock!123, and the same attacker hostname. GuidePoint has seen the pattern across multiple RaaS programs, pointing to one affiliate moonlighting across gangs and cutting its employers out of the payday.

Paying the supposed rescuers gives no assurance the data disappears. If a stranger knows about an unreported breach and offers to fix it cheap, that call is likely part of the attack itself.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.