Ransomware affiliate masquerades as a recovery service to hijack victims' payments
Researchers say a group calling itself “Ransom Busters” pretends to rescue ransomware victims, offering cheaper data-recovery deals while siphoning off the ransom money for itself.
GuidePoint Security identified a new scam in which a faction named “Ransom Busters” reaches out to ransomware victims ahead of any public disclosure, offering to purge stolen data and retrieve encryption keys for a fraction of the demanded ransom, typically between $20,000 and $60,000. The firm’s Research and Intelligence Team (GRIT) assessed with moderate confidence that the group is not an independent recovery service but a ransomware affiliate working for several ransomware-as-a-service operations, including those linked to DragonForce, Settra and Anubis.
Email communications claimed the attackers had breached the ransomware gangs themselves and accessed the same data sets, a claim supported by forensic evidence showing identical toolchains—SoftPerfect Network Scanner, s5cmd, and the Remotely remote-management utility installed via PowerShell—across two separate incidents. Both intrusions also featured a backdoor account using the password “Numlock!123” and the same hostname, “DESKTOP-BBETH6K.” GuidePoint cautions that victims who pay the impostor service receive no assurance that their data will be destroyed, and the scheme highlights the growing mistrust even among criminal actors. The discovery underscores the need for organizations to verify the legitimacy of any third-party recovery offers before transferring funds.
Why it matters
It shows how cyber-criminals are turning on each other, creating new fraud risks for ransomware victims.
In this story
