Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Because apparently even ransomware gangs can't trust the people they do business with
A ransomware affiliate known as Ransom Busters is allegedly targeting fellow extortionists by posing as a recovery firm. The group offers to recover encrypted files for a smaller fee than the original ransom demand. However, according to researchers at GuidePoint Security, Ransom Busters is not an independent recovery team, but rather a ransomware affiliate working across multiple ransomware-as-a-service operations.
The researchers found that Ransom Busters approached victims before the ransomware attacks became public, claiming it had discovered stolen data on the criminals' servers and could delete the data and retrieve encryption keys for a price of $20,000 to $60,000. The intrusions shared specific fingerprints, including the use of SoftPerfect Network Scanner, s5cmd, and Remotely remote-management tool.
The attackers also created a local backdoor account with the same password in both environments. This suggests that one affiliate is likely moonlighting across multiple gangs and stealing the payment intended for their employers. Paying the supposed rescuers does not guarantee that the stolen information will be removed.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.