Ransomware crook poses as recovery firm to steal payments from fellow extortionists

← Back to the feed

Ransomware crook poses as recovery firm to steal payments from fellow extortionists

The Register · 2 hours ago

Security researchers at GuidePoint have uncovered a scam in which a criminal calling itself "Ransom Busters" contacts ransomware victims before their data leak becomes public, offering to delete stolen files and hand over decryption keys for a fraction of the original ransom. Rather than being a genuine recovery outfit, GuidePoint's Research and Intelligence Team assesses with "moderate confidence" that it is actually a ransomware affiliate double-crossing the very gangs it works with, diverting victim payments away from its criminal partners.

GuidePoint identified the scheme while investigating attacks tied to the DragonForce, Settra and Anubis ransomware operations, with Ransom Busters demanding between $20,000 and $60,000 (roughly £15,700 to £47,000) and proving access to the stolen data as leverage. Two investigated cases shared identical technical fingerprints, including the same reconnaissance and file-exfiltration tools, a backdoor account using the password "Numlock!123", and the hostname "DESKTOP-BBETH6K" — evidence pointing to a single affiliate operating across multiple ransomware-as-a-service groups. GuidePoint warned that paying these self-styled rescuers offers no guarantee the stolen data will actually be deleted.

  • A ransomware affiliate is scamming fellow criminals' victims for cash
  • "Ransom Busters" poses as a recovery service, demanding $20,000-$60,000
  • Shared hacking tools and credentials link it to DragonForce, Settra and Anubis attacks

Cybersecurity Technology

Read the full article at the source →