Science
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Key Points
A ransomware affiliate appears to have found a new way to squeeze victims for cash: pose as the good guy and undercut the criminals it was working with. Researchers at GuidePoint Security say an outfit calling itself "Ransom Busters" has been contacting ransomware victims before their attacks become public, offering to recover encrypted files and delete stolen data for a considerably smaller payment than the original extortion demand. The catch, according to GuidePoint's Research and...
A ransomware affiliate appears to have found a new way to squeeze victims for cash: pose as the good guy and undercut the criminals it was working with. Researchers at GuidePoint Security say an outfit calling itself "Ransom Busters" has been contacting ransomware victims before their attacks become public, offering to recover encrypted files and delete stolen data for a considerably smaller payment than the original extortion demand. The catch, according to GuidePoint's Research and Intelligence Team (GRIT), is that Ransom Busters isn't an enterprising band of ransomware hunters at all. The researchers assess with "moderate confidence" that it's a ransomware affiliate working across several ransomware-as-a-service operations and attempting to steer payments away from its criminal partners. GuidePoint came across Ransom Busters while investigating attacks linked to DragonForce, Settra, and Anubis. The outfit emailed victims claiming it had hacked the ransomware gangs themselves and discovered their stolen data on the crooks' servers. Ransom Busters claimed it could delete that data and retrieve encryption keys, all for the bargain-basement price of between $20,000 and $60,000. It also demonstrated access to the same datasets held by the ransomware affiliate behind the attacks, GuidePoint said. That alone raised eyebrows, but the forensic evidence proved rather harder to explain away. GuidePoint examined two incidents in which Ransom Busters approached victims and found the intrusions shared a collection of unusually specific fingerprints. Both used SoftPerfect Network Scanner for reconnaissance, s5cmd to shovel data into AWS cloud storage, and the Remotely remote-management tool installed using PowerShell. More damningly, the attacker created a local backdoor account using the password "Numlock!123" in both environments. The same attacker-controlled hostname, "DESKTOP-BBETH6K," also turned up in both intrusions. This might be explained by ransomware operators sharing tools or a prebuilt attack environment. GuidePoint said it has seen the same activity across several separate RaaS programs, however, leading it to conclude that one affiliate is likely moonlighting across multiple gangs and then cutting its employers out of the payday. GuidePoint also warned that paying the supposed rescuers provides no assurance that stolen information will actually disappear. So if a mysterious stranger somehow knows you've been ransomwared before you've told anyone, and generously offers to make the whole problem disappear for $20,000, you may want to question how they got your number in the first place. ®