AUTO-UPDATED

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is impersonating a recovery service called Ransom Busters to extort victims by offering to delete stolen data for fees ranging from $20,000 to $60,000.

Key Points

  • GuidePoint Security’s GRIT team identified Ransom Busters as a likely malicious actor rather than a legitimate recovery firm.
  • The group contacts victims before attacks become public, suggesting they are the original attackers or have direct access to the ransomware infrastructure.
  • Forensic evidence links Ransom Busters to specific tools like SoftPerfect Network Scanner and a consistent backdoor password, 'Numlock!123'.
  • The group claims to exploit vulnerabilities in ransomware-as-a-service (RaaS) panels to access data stolen by gangs like DragonForce, Settra, and Anubis.
  • Cybersecurity firm Coveware confirmed similar interference, noting that this behavior is distinct from typical "ambulance chaser" tactics.

Why it Matters

This activity introduces a dangerous new layer of extortion where victims may pay multiple parties without any guarantee that their stolen data will remain private. It highlights growing instability within the ransomware ecosystem as affiliates increasingly bypass standard revenue-sharing models to maximize their own illicit profits.
BleepingComputer Published by Lawrence Abrams
Read original