Ransomware Hackers Pose as Recovery Firm, Demand Up to $60,000

In a concerning development, ransomware victims are now being targeted by entities masquerading as data recovery firms. These impostors, operating under the name ‘Ransom Busters,’ contact affected organizations shortly after an attack, offering services to retrieve encrypted files and delete stolen data. However, this approach is a deceptive tactic aimed at extracting additional payments from victims.

Security researchers have identified that ‘Ransom Busters’ is not a legitimate recovery service but rather an affiliate of ransomware groups. This entity exploits insider knowledge gained during the initial ransomware intrusion to present itself as a savior, thereby pressuring victims into making further payments. The operation has been linked to ransomware strains such as DragonForce, Settra, and Anubis.

The modus operandi involves ‘Ransom Busters’ claiming to have infiltrated the servers of the original ransomware attackers, gaining access to stolen data and encryption keys. They promise to return the encrypted files and ensure the deletion of any copies held by the attackers. For these services, they demand payments ranging from $20,000 to $60,000. However, evidence suggests that ‘Ransom Busters’ possesses the same data as the original attackers, indicating a direct connection rather than an independent recovery effort.

This tactic introduces significant legal and ethical concerns. Unauthorized access to another group’s servers, even if they belong to cybercriminals, may violate laws such as the Computer Fraud and Abuse Act. Moreover, legitimate data recovery services do not typically require payments to perform actions that could be deemed illegal.

Further analysis by security experts revealed consistent tools and methods used across multiple incidents involving ‘Ransom Busters.’ These include network scanning utilities, cloud data exfiltration tools, and remote management software. The recurrence of specific tools and techniques suggests that a single affiliate is orchestrating these deceptive recovery schemes across various ransomware campaigns.

For organizations that have fallen victim to ransomware, it is crucial to approach unsolicited recovery offers with skepticism. Engaging with trusted incident response teams and law enforcement agencies is essential. Victims should independently verify any claims made by recovery services and be aware that paying additional ransoms does not guarantee the deletion of stolen data.

This emerging trend underscores the evolving strategies of cybercriminals, who are continually seeking new avenues to exploit victims. Organizations must remain vigilant, enhance their cybersecurity measures, and foster a culture of skepticism towards unsolicited offers, especially in the aftermath of a ransomware attack.