A suspected ransomware affiliate is posing as a recovery service called Ransom Busters and contacting victims before their attacks become public, researchers warn.
The group claims it can provide decryption keys and delete stolen data from ransomware servers. It then asks victims to pay a separate fee for its services.
Researchers assess that Ransom Busters is likely not an independent recovery business. Instead, they believe it is a ransomware affiliate attempting to profit outside the normal revenue-sharing arrangements used by ransomware-as-a-service operations.
Ransom Busters contacts victims before public disclosure
Ransom Busters has emailed organisations shortly after ransomware attacks, asking to speak with senior executives or IT leaders.
The timing raised immediate concerns. Legitimate cybersecurity firms may offer help after an incident becomes public. However, Ransom Busters appeared to know about attacks that victims had not disclosed.
The group told victims that it had found vulnerabilities in ransomware operators’ administrative panels. It claimed that this access gave it control of stolen files, backups and encryption keys.
Ransom Busters allegedly offered to delete victim data from the infrastructure of several ransomware operations, including DragonForce, Settra and Anubis. The requested fees ranged from $20,000 to $60,000.
Researchers link the scheme to ransomware activity
Investigators reviewed two incidents involving the group and found overlapping tools, tactics and infrastructure.
In both cases, the attackers used the same network scanning, remote-management and data-transfer software. They also created a matching backdoor account and used the same attacker-controlled hostname.
Based on this evidence, researchers assess with moderate confidence that a single ransomware affiliate operates Ransom Busters across several ransomware-as-a-service groups.
The affiliate appears to use privileged access to contact victims directly. It then offers an alternative payment route that may allow it to keep the money rather than share it with the ransomware operation behind the attack.
Researchers said they had not seen a victim pay Ransom Busters. In one observed case, the victim paid the ransomware operation instead. The victim’s name and stolen data did not appear on the group’s leak site, and investigators found no evidence that Ransom Busters published the data outside the ransomware environment.
Victims should avoid unverified recovery offers
Ransomware negotiation specialists have also observed similar approaches. They say intermediaries have contacted publicly known victims under other names for years.
However, this case carries a greater risk because Ransom Busters contacted organisations before their incidents became public. That suggests access to information that an outside recovery provider should not have.
A separate party with access to stolen data can also complicate negotiations. Paying the original ransomware operation may no longer ensure that every actor with a copy of the data will honour an agreement not to leak it.
Victims should treat unsolicited recovery offers with extreme caution. They should work with trusted incident-response professionals, verify any claims independently and avoid sending payments to unknown third parties.


0 responses to “Ransom Busters Poses as Ransomware Recovery Firm”