Protect.Computer
NEWS

Ransom Busters: Ransomware Gang Poses as Incident Recovery Service

· 1 min read · Digital scams Data hijack
Ransom Busters: Ransomware Gang Poses as Incident Recovery Service

A ransomware affiliate operating under the name “Ransom Busters” has been caught running an unusual secondary scam: contacting organizations that were already hit by ransomware and offering — for a fee of $20,000 to $60,000 — to break into the ransomware group’s own servers and delete the stolen data. GuidePoint Research and Intelligence Team (GRIT) published a report describing the operation after responding to multiple incidents where victims received these unsolicited emails.

The pitch sounds like a lifeline. Ransom Busters claims it discovered vulnerabilities in the administrative panels used by ransomware-as-a-service (RaaS) groups and has been exploiting them for over three years. In messages addressed to a company’s CEO or IT leadership, the actor says it found victim data on those servers and offers to delete it — once paid. But GuidePoint’s investigation found the most likely explanation is that Ransom Busters is not a third party at all: the same attacker that conducted the original ransomware intrusion is also sending the recovery offer. The tools, infrastructure, and techniques across multiple victim environments were nearly identical: SoftPerfect Network Scanner for reconnaissance, s5cmd for exfiltrating data to AWS cloud storage, the Remotely RMM agent installed via PowerShell, and a backdoor local account with the password “Numlock!123”. The attacker-controlled hostname DESKTOP-BBETH6K appeared across two separate incidents. GuidePoint linked Ransom Busters activity to DragonForce, Settra, and Anubis ransomware operations.

Sources

Related reading