News

Ransom Busters Scam – A Ransomware Affiliate Robbing Its Own Gang

Two differently coloured hands reaching for a stolen data folder, both belonging to the same hooded figure, showing one affiliate running two extortion channels

“Ransom Busters” claims to be a vigilante crew that raids criminal servers. GuidePoint says it’s an insider skimming ransom money from the gangs it works for.

Victims of ransomware attacks are starting to receive suspicious emails, even though the companies haven’t reported being attacked.

They come from “Ransom Busters LTD” and ask to talk to either the CEO or Head of IT. They say they’ve been tracking the infrastructure used by ransomware gangs for three years and in doing so they discovered that your stolen data is being stored on their server. They’ll provide your data back, remove it from the gang’s server, and provide you with the key to unlock your systems, all for a fee.

It’s likely that this is just another example of a ransomware affiliate. As explained in research released yesterday by GuidePoint Security’s Research and Intelligence Team, Ransom Busters is likely an affiliate of a ransomware group, operating as a side-hustle which allows them to extract additional monies (beyond the ransom) paid by victims without sharing any of that money with the ransomware group that hired them.

According to GuidePoint’s GRIT, who assessed this situation with moderate confidence, this individual is probably an individual affiliate with access to multiple ransomware programs. They’re likely using that access to negotiate with the ransomware victim ahead of the organization that hired them.

The researchers reached this conclusion through conversations with Ransom Busters directly during a series of live incident response events.

So what tipped off GRIT? Timing.

Incident Response firms frequently cold-email ransomware victims after the victim appears on a leak site. However, Ransom Busters began reaching out long before that happened. This caused GRIT to flag the outreach as abnormal because Ransom Busters was aware of intrusions that hadn’t been made public. In fact, in some cases, none of the parties involved had confirmed the intrusion. There are only a few ways to know that an organization is currently experiencing an incident. Knowing you are inside the incident is one of them.

During GRIT’s engagement with Ransom Busters, the actor stated that it had identified vulnerabilities in the administrative panels associated with multiple ransomware-as-a-service operations and therefore controlled most of that infrastructure. The actor then provided proof of this assertion. They verified access to the exact same stolen dataset being held by the responsible affiliate. The cost to make that data go away ranged from $20,000 to $60,000.

Next came the portion of the conversation that broke the story wide open. When asked why a supposedly benevolent anti-ransomware operation charged money for services rendered, Ransom Busters stated that providing free services could jeopardize its continued access to the resources used by the criminal organizations. This doesn’t make sense. Regardless of whether a victim chooses to pay for removal of their data, has absolutely no bearing on whether you continue to have access to the backend of a gang. It appears as if this person responded to an unplanned question they had not previously anticipated.

GRIT also identifies a glaring flaw in the altruistic justification for the activities described above. Deleting files on behalf of a legitimate client using resources obtained by hacking into a rival organization, while accepting payment for such actions, could potentially violate the Computer Fraud and Abuse Act. Thus, legitimate entities cannot operate as criminals for a profit.

Two intrusions, one operator

Forensic evidence supports this transition from speculative to assessment.

GuidePoint’s DFIR team investigated two distinct incidents involving contact by Ransom Busters to the victim(s). Incidents related to ransomware infections tend to mirror each other due to affiliates utilizing similar tools/playbooks. However, in addition to similarities in playbooks/tools utilized within each environment, there existed greater similarity than would be expected based solely upon utilization of common playbooks/tools:

  • Internal reconnaissance was conducted using SoftPerfect Network Scanner in both.
  • Use of s5cmd to transfer stolen data to AWS Cloud Storage in both;
  • Remote installation via an RMM tool utilizing a PowerShell script in both;
  • Creation of identical local backdoor accounts, utilizing the identical password “Numlock!123,” in both.
  • Utilization of identical attacker-hostname “DESKTOP-BBETH6K” in both.

Standardized tooling across affiliates operating within a single program is possible. Choice of passwords is virtually limitless. Identical password choices indicate use of a singular set of hands. Similarly, repeated utilization of the same hostname further reinforces this point.

While overlap among similar tools used by multiple affiliates may exist across various ransomware programs, the repeated presence of overlapping elements (passwords/hostnames), specifically across disparate ransomware brands (DragonForce/Settra/Anubis), clearly indicates that there exists a single operative, using multiple affiliate names, conducting side hustles against their own employers.

Beyond its potential impact as an actual scam, this matter represents a significant issue for the ransomware economy beyond the act itself.

Why it matters past the scam itself

In essence, when stripped of the veneer of being an altruistic vigilante, this entity is simply another affiliate attempting to steal from its employer.

Revenues generated from RaaS models rely upon affiliates directing payments through their respective operation and taking a percentage thereof. An affiliate who negotiates with victims independently, outside of their agreement with their employer, and offers reduced payment terms for immediate resolution (which remain independent of any funds paid by the employer) constitutes revenue skimming and simultaneously damages the brand of their employer. GuidePoint notes that this individual has demonstrated it will “betray even its own criminal associates for financial gain.”

This creates issues regarding trust within the overall ransomware economy. How these affected groups respond should be monitored. Historically, affiliate theft has been addressed by these groups through methods including public shaming on forums, doxing, and/or blacklisting. If the impacted groups determine who is behind the persona, it is likely that repercussions will occur publicly.

From a victim perspective, however, this means that there exists no third-party entity capable of retrieving or “un-stolen” your data. GRIT also points out that threat actors have repeatedly demonstrated possession of multiple copies of exfiltrated data for future resale or extortion purposes. Therefore, paying a fee for data removal represents little more than an assurance from a criminal with ample motivation to break such assurances, particularly given that this individual has already shown he will betray promises made to his fellow associates.

If this lands in your inbox

Detection criteria include:

  • No prior solicitation by unsolicited contact regarding an incident that has not yet been made public
  • Requests directed toward CEOs or IT Leadership as opposed to Security Contacts
  • Usage of free or privacy-focused email addresses lacking verifiable corporate domains
  • Assertions that the actor has accessed/hacked the attacker
  • Fee ranges between $20,000-$60,000 for data removal

Report it to your incident response team rather than replying. If the email is real in the only sense that matters, meaning the sender genuinely has your data, then it’s confirmation you’re in an active breach. That’s information for your responders. It isn’t a negotiation to open on your own.

Organizations that want earlier warning of their own data surfacing can compare options in our dark web monitoring reviews, and CISA’s #StopRansomware advisories remain the reference point for reporting and response guidance.

Related reading

Sources

Written by hanna

I'm Hanna, a security consultant based in Berlin with more than twelve years of experience across offensive and defensive security. I started out on a blue team chasing alerts at 3 a.m., moved into red teaming because I wanted to understand the other side of the console, and now run an independent practice advising companies on threat intelligence, penetration testing, incident response planning, and security architecture.

0 0 votes
Article Rating
Subscribe
Notify of
guest
1 Comment
Oldest
Newest Most Voted
trackback

[…] perspective, to actually spend it. That’s exactly the kind of centralized weak point our look at the Ransom Busters honeytrap scam also touched on, criminals depending on infrastructure and relationships just as much as legitimate […]