Scammers Pose as Ransomware Recovery Firms

Photo: BleepingComputer
Quick answer
The fraudulent group Ransom Busters impersonates a ransomware recovery service to intercept payments from victims.
Cybersecurity experts from GuidePoint Security have identified a fraudulent scheme in which attackers impersonate data recovery services following ransomware attacks. The group, operating under the name "Ransom Busters," contacts victims before attacks become public, offering data decryption and deletion of stolen information for a fee.
According to researchers, the proposed amounts range from $20,000 to $60,000. Ransom Busters claim to have accessed encryption keys and victim data through vulnerabilities in RaaS administrative panels, including DragonForce, Settra, and Anubis. However, analysis of two incidents suggests that the service is likely a rogue affiliate responsible for the attacks themselves.
In both cases, the attackers used identical tools: SoftPerfect Network Scanner, s5cmd, and Remotely. Identical tactics were also observed, including the creation of a local account with the password "Numlock!123" and the use of the same host "DESKTOP-BBETH6K." Experts believe Ransom Busters is a single affiliate working with multiple RaaS operations to intercept victim payments.
Coveware, a company specializing in negotiations with cybercriminals, confirmed encountering similar cases. According to Elizabeth Cookson, Senior Director of Incident Response, such "intermediaries" are becoming more common, but they typically act after attacks are published. The activity of Ransom Busters in unpublished incidents is particularly concerning, as it increases risks for victims.
Experts warn that such schemes undermine trust within the RaaS ecosystem and may lead to a rise in fraud by affiliates seeking additional profits at the expense of victims.
Common questions
- Who are Ransom Busters?
- Ransom Busters is a group posing as a data recovery service for ransomware victims. Experts suspect it is a rogue RaaS affiliate attempting to divert payments from victims.
- How do Ransom Busters learn about unpublished attacks?
- They likely exploit vulnerabilities in RaaS administrative panels to access victim data and encryption keys before attacks are publicly disclosed.
- Why do experts advise against paying Ransom Busters?
- Payments do not guarantee data deletion, and scammers may reuse or leak the information. This also erodes trust in legitimate negotiators and RaaS operations.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml