Ransomware Affiliate Poses as Recovery Firm to Re-Extort Victims After Data Theft | #ransomware | #cybercrime


Ransomware Affiliate Re-Extorts Victims

GuidePoint Security’s Research and Intelligence Team (GRIT) has uncovered a ransomware extortion tactic in which an alleged recovery service, “Ransom Busters,” contacts victims before their cyberattack becomes public.

The group claims it can retrieve stolen files, destroy criminal backups, and provide ransomware decryption keys.

However, GRIT assesses with moderate confidence that Ransom Busters is actually a ransomware affiliate attempting to divert payments from the original ransomware operation.

The scheme has been observed in incidents involving DragonForce, Settra, and Anubis ransomware activity.

Instead of using a standard ransom note alone, the suspected affiliate presents itself as a helpful third party that has supposedly breached ransomware gangs’ infrastructure.

Victims receive emails from “Ransom Busters LTD” requesting contact with CEOs or IT leaders. The emails state that the group discovered stolen company data on ransomware servers and can delete it for a fee.

It also claims to have access to the gangs’ encryption-key storage and administrative panels.

The offer is suspicious because legitimate cybersecurity firms generally contact ransomware victims only after an incident becomes publicly known.

Ransom Busters, however, contacted organizations while their attacks were still private. That level of knowledge strongly suggests the actor already had access to the stolen data or details of the intrusion.

Ransomware Affiliate Re-Extorts Victims

GRIT analyzed two ransomware incidents where Ransom Busters approached the victims. Investigators found several technical overlaps between the intrusions.

Both environments contained SoftPerfect Network Scanner, used for internal network reconnaissance.

The attackers also used s5cmd to move stolen data to AWS cloud storage and deployed the Remotely remote monitoring and management tool through a PowerShell script.

More importantly, the attackers created a local backdoor account using the same password: Numlock!123. The hostname DESKTOP-BBETH6K also appeared in both intrusions.

Any one of these indicators could reflect a shared ransomware playbook. Together, they provide a stronger correlation.

GRIT noted that the same activity has appeared across several ransomware-as-a-service operations, making it less likely that Ransom Busters is an independent recovery firm.

The suspected affiliate demanded between $20,000 and $60,000 to delete stolen data from ransomware servers. It claimed that payment was necessary to preserve its access to criminal infrastructure.

GRIT found this explanation unconvincing, since a victim’s payment would not logically determine whether the actor could access those systems.

The case highlights an evolving ransomware model, affiliates may attempt to re-extort victims independently after stealing their data.

By posing as a recovery service, the actor creates an alternative payment channel while exploiting the victim’s fear of data exposure.

There is no reliable assurance that criminals will delete stolen data after receiving payment. Threat actors may retain copies for future sale, leaks, or repeat extortion attempts.

Organizations receiving unsolicited recovery offers should immediately notify their incident-response provider and preserve the emails, sender domains, payment demands, and any linked indicators. They should avoid negotiating directly with unknown third parties.

Law enforcement and reputable digital forensics and incident-response firms remain the safest resources during ransomware events.

A promise to “recover” data for a fee especially from an entity aware of a non-public breach should be treated as a likely scam or an additional layer of extortion.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN



Click Here For The Original Source.

——————————————————–

..........

.

.