A suspected ransomware affiliate is impersonating a recovery service called Ransom Busters to extort victims by offering to delete stolen data for fees ranging from $20,000 to $60,000.
Key Points
- GuidePoint Security’s GRIT team identified Ransom Busters as a likely malicious actor rather than a legitimate recovery firm.
- The group contacts victims before attacks become public, suggesting they are the original attackers or have direct access to the ransomware infrastructure.
- Forensic evidence links Ransom Busters to specific tools like SoftPerfect Network Scanner and a consistent backdoor password, 'Numlock!123'.
- The group claims to exploit vulnerabilities in ransomware-as-a-service (RaaS) panels to access data stolen by gangs like DragonForce, Settra, and Anubis.
- Cybersecurity firm Coveware confirmed similar interference, noting that this behavior is distinct from typical "ambulance chaser" tactics.