What's Happening?
A cybercriminal group operating under the name 'Ransom Busters' is proactively contacting organizations that have been victims of ransomware attacks, offering to delete stolen data from ransomware groups' servers in exchange for a payment ranging from $20,000
to $60,000. GuidePoint Research and Intelligence Team (GRIT) has reported on this anomalous activity, noting that while cybersecurity firms typically offer recovery services after an attack becomes public, Ransom Busters is reaching out directly to victims. The group claims to have exploited vulnerabilities in administrative panels maintained by Ransomware-as-a-Service (RaaS) groups and to have been accessing these servers for over three years. They assert that they have found data stolen from the victim companies on these servers and promise to help regain access to files and delete all backups held by the ransomware group upon payment.
Why It's Important?
This development signifies a concerning evolution in the ransomware landscape, where cybercriminals are not only extorting victims for encrypted data but also attempting to profit by posing as 'saviors' who can recover or delete stolen information. This tactic introduces an additional layer of deception and risk for U.S. businesses already grappling with the aftermath of cyberattacks. The claim by Ransom Busters to delete data from other ransomware groups' servers is highly dubious and likely a further extortion attempt, as there is no guarantee that such data would actually be deleted. This practice could lead to victims paying multiple ransoms without any assurance of data security, potentially violating the U.S. Computer Fraud Abuse Act. The targeting of financial services firms, including hedge funds and private equity, highlights the significant financial stakes and the sophisticated nature of these cybercriminal operations, which can have substantial economic impacts on affected organizations.
What's Next?
Cybersecurity experts, including GuidePoint, strongly advise against engaging with or making payments to groups like Ransom Busters, as there is no guarantee of data deletion or recovery, and such actions may inadvertently fund further criminal activities. Organizations that have been contacted by Ransom Busters should treat these communications as part of the ongoing cyber threat and focus on established incident response protocols. Law enforcement agencies will likely continue to investigate these types of deceptive extortion schemes. The broader cybersecurity community will need to develop and disseminate strategies to help businesses identify and resist these new forms of cyber extortion, emphasizing that criminal actors cannot be trusted. This situation also underscores the need for robust preventative cybersecurity measures and comprehensive data backup and recovery plans to minimize the impact of ransomware attacks.
Beyond the Headlines
The emergence of 'Ransom Busters' reflects a growing fragmentation and specialization within the cybercrime ecosystem. This group's modus operandi, which involves exploiting vulnerabilities in RaaS infrastructure and then contacting victims, suggests a complex interplay between different cybercriminal entities. It raises ethical and legal questions about the extent to which victims should engage with any party claiming to offer data recovery services from stolen data, especially when those parties are themselves operating outside the law. The financial motivation behind these attacks, with average extortion amounts reaching hundreds of thousands of dollars, underscores the lucrative nature of cybercrime and the continuous innovation by threat actors to maximize their profits. This trend also highlights the challenges faced by law enforcement and cybersecurity professionals in tracking and disrupting these evolving criminal enterprises, which often operate across international borders and leverage sophisticated techniques to evade detection.








