What's Happening?
A ransomware affiliate operating under the name 'Ransom Busters' is reportedly contacting victim organizations, claiming to have hacked into ransomware groups' servers and offering to delete stolen data in exchange for a fee ranging from $20,000 to $60,000.
GuidePoint Research and Intelligence Team (GRIT) has identified this unusual modus operandi, noting that cybersecurity firms typically offer recovery services only after an attack becomes public. Ransom Busters asserts that it has found vulnerabilities in administrative panels of Ransomware-as-a-Service (RaaS) groups and has been infiltrating their servers for over three years. The group claims to have discovered victims' stolen data on these servers and offers to help regain access to files and delete backups held by the ransomware groups in exchange for payment. GRIT has observed this activity in incidents involving threat groups such as DragonForce, Settra, and Anubis.
Why It's Important?
This development introduces a complex and ethically dubious layer to the ransomware landscape, as it involves a third party claiming to act as an intermediary between victims and their original attackers, or potentially being an affiliate of the attackers themselves. GuidePoint suggests that the 'Ransom Busters' are likely a ransomware affiliate rather than a legitimate organization, as their actions could violate the U.S. Computer Fraud Abuse Act. This situation creates a dilemma for victim organizations, who might be desperate to recover their data and avoid further exposure, but face the risk of engaging with a potentially criminal entity. Paying such a group offers no guarantee that data will actually be deleted or that further extortion will not occur. This tactic could also undermine trust in legitimate cybersecurity and incident response services, making it harder for victims to discern credible assistance from deceptive schemes.
What's Next?
Cybersecurity experts are advising organizations to treat 'Ransom Busters' as a hoax, emphasizing that payment to any criminal party does not guarantee the deletion of stolen data. The emergence of such groups highlights the evolving and increasingly sophisticated tactics employed by cybercriminals to extort money. Organizations are urged to strengthen their cybersecurity defenses, implement robust backup strategies, and work with trusted cybersecurity professionals in the event of a ransomware attack. Law enforcement agencies will likely investigate these activities, as they represent a new form of cybercrime that exploits the distress of ransomware victims. The incident also underscores the need for greater awareness among businesses about the various forms of cyber extortion and the importance of verifying the legitimacy of any entity offering recovery services.
Beyond the Headlines
The 'Ransom Busters' phenomenon blurs the lines between victim and perpetrator, introducing a new ethical quandary in the fight against cybercrime. If the 'Ransom Busters' are indeed affiliates of ransomware groups, it represents a cynical evolution of the extortion model, where the same actors profit from both the initial attack and the 'recovery' process. This could lead to a deeper erosion of trust in the digital ecosystem and complicate efforts to combat ransomware, as victims might be lured into paying these intermediaries, inadvertently funding the very criminal enterprises that attacked them. The situation also raises questions about the effectiveness of current legal frameworks in addressing such complex, multi-layered cyber-extortion schemes, and the potential for international cooperation to track and prosecute these actors. It underscores the continuous need for vigilance and critical assessment of any offers of assistance following a cyberattack.











