HomeMalware & ThreatsRansom Busters Claims to Have Hacked Ransomware Servers, Demands Victims Pay Up...

Ransom Busters Claims to Have Hacked Ransomware Servers, Demands Victims Pay Up to $60,000

Published on

spot_img

The Rise of ‘Ransom Busters’: A New Threat in Cybersecurity

In an unsettling revelation for organizations grappling with the repercussions of ransomware attacks, an affiliate group known as Ransom Busters has emerged. This group has been proactively targeting victim organizations with unsolicited emails, claiming to offer a peculiar service: the deletion of stolen data from the servers of ransomware groups, but only for a fee ranging between $20,000 to $60,000.

A recent report from GuidePoint Research and Intelligence Team (GRIT), which has been closely monitoring the situation, underscored the unusual nature of these communications. Typically, cybersecurity firms reach out to companies post-attack, once the incidents become public knowledge. However, Ransom Busters is breaking this mold by contacting victims directly and offering assistance amidst their crises.

According to GRIT, the group asserts it has uncovered vulnerabilities in administrative panels maintained by ransomware-as-a-service (RaaS) operations and claims to have had unauthorized access to their servers for over three years. In their outreach, Ransom Busters requests contact with the executives of the target organizations, purporting to have evidence of the data stolen from the companies.

The motivations of this financially motivated entity become clear: by asking victims to pay between $20,000 and $60,000, they claim to facilitate the recovery of critical files and data while simultaneously erasing backups held by the perpetrators. GRIT’s report mentions that they have seen these tactics play out during responses to incidents tied to notorious ransomware groups like DragonForce, Settra, and Anubis. What is particularly alarming is the assertion that this situation is unlikely to be the act of a legitimate organization, as it could lead to violations of the U.S. Computer Fraud Abuse Act.

Justin Timothy, a Principal Consultant at GRIT, articulated a significant concern, stating, “The insinuation that these individuals were either misrepresenting their origins or operating illegally further complicates the narrative around their authenticity.” When asked why they demand payment for their assistance, Ransom Busters provided an ambiguous justification: that working without financial compensation would jeopardize their continued access to the infrastructure of the original threat actors.

An in-depth analysis of two separate incidents involving the group reveals striking similarities in their operations. Ransom Busters employed various tools, including SoftPerfect Network Scanner for reconnaissance, the data exfiltration command-line tool s5cmd to transfer data to cloud storage, and a remote monitoring and management (RMM) tool, installed via PowerShell scripts. Additionally, researchers found a consistent pattern with local backdoor accounts being created using the password “Numlock!123” across different intrusions. Moreover, the detection of the same attacker-controlled hostname, DESKTOP-BBETH6K, in both incidents raises the suspicion that a single operator or affiliate is orchestrating these attacks.

The ramifications for potential ransomware victims are stark. Timothy remarked, “Criminal actors cannot be trusted, and they may resort to deceitful tactics to extract even further extortion payments from their targets.” He concluded that while Ransom Busters may appear to be offering a helping hand, they are likely manipulating the fear and urgency of victims for financial gain. Payment to any criminal operation not only fails to guarantee the deletion of stolen data but often leads to further complications, as these "benefactors" may not have the victims’ best interests at heart.

In an interesting related development, GuidePoint has brought attention to the sustained operations of UNC6671, an adversary-in-the-middle (AitM) group that has been ruthlessly targeting various sectors, especially financial institutions, since April. The group operates under different extortion brands—such as Falcon, Helix, Pink, and Redact—all of which have contributed to over $8 million in payments across 15 Bitcoin wallets. Statistics show an alarming increase in the sophistication of these cybercriminals, as they increasingly engage in targeted attacks on large organizations, often referred to as “big game hunting.”

With a diving interest in hacking and credential theft, UNC6671 employs a custom system called Work Panel that streamlines their operations, setting a new standard in the landscape of cybercrime. The operations are meticulously designed to separate roles within their criminal framework, shielding individuals from the broader scope of the illicit activities being conducted. This organizational structure illustrates a troubling evolution toward a more industrialized space within cybercrime.

As the ransomware landscape continues to shift, new groups, such as Tengu and CRPx0, are emerging, each with their own unique strategies and target demographics. Notably, while some groups target specific regions, others demonstrate a wide net, showcasing the adaptive and changing nature of ransomware threats globally.

Overall, the emergence of Ransom Busters brings to light not only the complexities of the ransomware ecosystem but also emphasizes the importance for organizations to remain vigilant and fortified against all forms of cyber threats. The clear message is that reliance on dubious offers of help from criminal actors can only lead to more jeopardies, reinforcing the age-old adage that if something appears too good to be true, it likely is.

Source link

Latest articles

ETSI Proposes 17 Cybersecurity Standards for the EU Cyber Resilience Act

The European Telecommunications Standards Institute (ETSI) has embarked on a pivotal journey to enhance...

Three-Quarters of Ransomware Attacks Focus on Mid-Market Firms

Title: Ransomware Strikes: Mid-Sized Organizations Bear the Brunt A recent study conducted by the third-party...

OpenAI Urges Organizations to Prioritize Cybersecurity Automation Amid Rising AI-Driven Attacks

OpenAI Urges Quick Automation of Cybersecurity Functions Amid Rising AI Threats OpenAI has raised an...

Microsoft Addresses Critical One-Click Copilot Vulnerability Nearly Eight Months After Discovery

In recent discussions within the cybersecurity community, a significant warning has emerged regarding the...

More like this

ETSI Proposes 17 Cybersecurity Standards for the EU Cyber Resilience Act

The European Telecommunications Standards Institute (ETSI) has embarked on a pivotal journey to enhance...

Three-Quarters of Ransomware Attacks Focus on Mid-Market Firms

Title: Ransomware Strikes: Mid-Sized Organizations Bear the Brunt A recent study conducted by the third-party...

OpenAI Urges Organizations to Prioritize Cybersecurity Automation Amid Rising AI-Driven Attacks

OpenAI Urges Quick Automation of Cybersecurity Functions Amid Rising AI Threats OpenAI has raised an...