A supposed ransomware recovery provider calling itself Ransom Busters is approaching organizations shortly after they are attacked and offering to provide decryption keys and erase stolen information for tens of thousands of dollars. Security researchers believe the operation may actually be controlled by a ransomware affiliate involved in the original intrusions.
The unusual activity was identified by GuidePoint Security’s Research and Intelligence Team (GRIT) while investigating several ransomware incidents. Victims received unsolicited emails from Ransom Busters offering assistance before information about their attacks had become public.
That timing raised an immediate question: how did an apparently independent recovery service know which organizations had recently been compromised? Ransom Busters provided its own explanation. It claimed to have discovered vulnerabilities in administrative panels operated by ransomware-as-a-service (RaaS) groups, supposedly allowing it to retrieve victims’ encryption keys and access data stolen during attacks. It offered to remove information held on infrastructure associated with ransomware operations including DragonForce, Settra and Anubis.
Prices for the purported recovery services ranged from $20,000 to $60,000. However, GRIT’s investigation uncovered technical similarities that point toward a different explanation. Evidence from two incidents linked the attacks through common tools and infrastructure. Both involved SoftPerfect Network Scanner, the s5cmd command-line utility, and the Remotely remote management tool.
Researchers also observed the creation of a local backdoor account using the same “Numlock!123” password. The incidents additionally shared the attacker-controlled hostname “DESKTOP-BBETH6K.”
Combined with activity overlapping several RaaS operations, these similarities led GRIT to assess with moderate confidence that Ransom Busters is probably a single ransomware affiliate rather than an independent recovery provider.
Under that theory, the affiliate could be attempting to profit twice from compromised organizations. After participating in ransomware attacks through established RaaS operations, the same actor could privately approach victims under the Ransom Busters identity and offer access to information or encryption keys obtained through its position within the ransomware ecosystem.
Such an arrangement could also allow the affiliate to divert money that would otherwise be shared with the operators of the ransomware service.
Researchers have not identified a victim that paid Ransom Busters. In one investigated incident, however, the organization paid the ransomware operation responsible for the attack instead. The victim subsequently did not appear on that operation’s public leak site, and researchers found no evidence that Ransom Busters separately released its information.
