Ransomware Affiliate Creates 'Recovery' Service to Divert Payments

AI-generated image · US National Wire
A criminal actor posing as 'Ransom Busters' is undercutting ransomware gangs to steal fees from victims.
A ransomware affiliate is operating a shadow-service layer designed to divert extortion payments away from criminal partners, according to reporting from The Register.
Researchers from GuidePoint Security's Research and Intelligence Team (GRIT) identified an outfit calling itself "Ransom Busters" that contacts victims of ransomware attacks before the incidents are made public. The group offers to delete stolen data and recover encrypted files for payments ranging between $20,000 and $60,000—amounts significantly lower than the original extortion demands. To build credibility, Ransom Busters claims to have hacked the ransomware gangs and discovered the stolen data on the criminals' own servers.
GuidePoint's investigation linked this activity to attacks involving Settra, Anubis, and DragonForce. The researchers assessed with "moderate confidence" that Ransom Busters is actually a ransomware affiliate working across multiple ransomware-as-a-service (RaaS) operations.
Forensic evidence revealed the same attacker fingerprints in two separate incidents, including the use of s5cmd for AWS cloud storage data transfers, SoftPerfect Network Scanner for reconnaissance, and the Remotely remote-management tool. Most notably, the attacker used the same hostname, "DESKTOP-BBETH6K," and the same password, "Numlock!123," for local backdoor accounts in both environments.
GuidePoint warned that these "recovery" payments offer no guarantee that stolen information will be deleted, noting that the affiliate is essentially moonlighting across gangs to cut its employers out of the payday.

