Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Scammers pose as ransomware recovery agents, but just go on to steal more from victims

Ransom Busters are not an actual ransomware recovery firm - they're ransomware affiliates looking to steal your money, too.

Scammers pose as ransomware recovery agents, but just go on to steal more from victims

Ransomware attackers have developed a new tactic, posing as ransomware recovery agents, to steal more money from victims. GuidePoint Security, a cybersecurity firm, observed this phenomenon after being called to multiple ransomware attacks on their clients. The attackers, posing as "Ransom Busters", offered to delete stolen files from the attackers' servers and provide decryption keys for $20,000 to $60,000.

However, researchers believe that Ransom Busters are likely just affiliates of the ransomware services, rather than genuine recovery firms, and are possibly even the ones who initially infected the companies. The firms using the same software, tactics, and identifiers suggest that it is the same group behind both the ransomware attacks and the supposed recovery.

Fortunately, no one has paid Ransom Busters for their offer, and the victim who paid the actual ransom demand had their files remain secure.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Thursday 20 August →