Ransom Busters are “hackers-liberators” who delete stolen data for $ 60000. Only before that they are kidnapped

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
392
Reaction score
635
Deposit
0$
Victims of ransomware faced a new scheme: soon after the attack, they write an unknown company that already knows about the stolen data and offers for money to remove them from criminals. GuidePoint Security experts believe that a participant in several criminal operations is hiding behind the “helpers” of Ransom Busters.

Representatives of Ransom Busters LTD contacted the organizations even before the information about the incidents became public. In the letters, the senders asked to connect them with the head of the company or IT unit and claimed to have found stolen files on ransomware servers.

Ransom Busters said it allegedly finds vulnerabilities in the management panels of criminal services and gains control over almost all of their infrastructure. The senders promised to return the files, destroy backup copies of the stolen data and get the keys to decrypt. GRIT met such a scheme in the investigation of attacks related to DragonForce, Settra and Anubis.

For the removal of stolen information, Ransom Busters required $20,000 to $60,000. During the inspection, the senders were able to confirm that they had access to the same dataset that the original extortion had. According to GRIT, this awareness is explained simply: Ransom Busters is a participant of partner programs of extortion, which tries to intercept part of the ransom from its own accomplices.


The results of the two investigations were prompted by this conclusion. In both networks, the attacker used SoftPerfect Network Scanner to scout the infrastructure, s5cmd, to send data to Amazon Web Services cloud storage, and the Remotely remote control facility installed through PowerShell. In addition, the offender created a local account with the same password Numlock!123 and used the computer name DESKTOP-BBETH6K.

The coincidence of individual instruments does not yet prove the connection between attacks. However, GuidePoint found the same set of techniques in the incidents of several different affiliate programs, after which the Ransom Busters appeared. Therefore, GRIT with moderate confidence links the appeals of “rescuers” with one participant who works with several ransomware operators at once.

Ransom Busters' claims that they were unauthorized to infiltrate the servers of criminals also raise legal questions. Such actions may fall under the American law on computer fraud and abuse. The U.S. Department of Justice separately points out that a good-faith security analysis should not serve as a cover to extort money.

GuidePoint warns : if you pay Ransom Busters, it does not guarantee that the data will be deleted. Criminals can save additional copies, sell information or later demand money again. After receiving an unexpected offer to “return” or delete stolen data for a fee, companies must send a message to their incident response team and contact law enforcement.
 
Top Bottom