The Rise of ‘Ransom Busters’: A New Threat in Cybersecurity
In an unsettling revelation for organizations grappling with the repercussions of ransomware attacks, an affiliate group known as Ransom Busters has emerged. This group has been proactively targeting victim organizations with unsolicited emails, claiming to offer a peculiar service: the deletion of stolen data from the servers of ransomware groups, but only for a fee ranging between $20,000 to $60,000.
A recent report from GuidePoint Research and Intelligence Team (GRIT), which has been closely monitoring the situation, underscored the unusual nature of these communications. Typically, cybersecurity firms reach out to companies post-attack, once the incidents become public knowledge. However, Ransom Busters is breaking this mold by contacting victims directly and offering assistance amidst their crises.
According to GRIT, the group asserts it has uncovered vulnerabilities in administrative panels maintained by ransomware-as-a-service (RaaS) operations and claims to have had unauthorized access to their servers for over three years. In their outreach, Ransom Busters requests contact with the executives of the target organizations, purporting to have evidence of the data stolen from the companies.
The motivations of this financially motivated entity become clear: by asking victims to pay between $20,000 and $60,000, they claim to facilitate the recovery of critical files and data while simultaneously erasing backups held by the perpetrators. GRIT’s report mentions that they have seen these tactics play out during responses to incidents tied to notorious ransomware groups like DragonForce, Settra, and Anubis. What is particularly alarming is the assertion that this situation is unlikely to be the act of a legitimate organization, as it could lead to violations of the U.S. Computer Fraud Abuse Act.
Justin Timothy, a Principal Consultant at GRIT, articulated a significant concern, stating, “The insinuation that these individuals were either misrepresenting their origins or operating illegally further complicates the narrative around their authenticity.” When asked why they demand payment for their assistance, Ransom Busters provided an ambiguous justification: that working without financial compensation would jeopardize their continued access to the infrastructure of the original threat actors.
An in-depth analysis of two separate incidents involving the group reveals striking similarities in their operations. Ransom Busters employed various tools, including SoftPerfect Network Scanner for reconnaissance, the data exfiltration command-line tool s5cmd to transfer data to cloud storage, and a remote monitoring and management (RMM) tool, installed via PowerShell scripts. Additionally, researchers found a consistent pattern with local backdoor accounts being created using the password “Numlock!123” across different intrusions. Moreover, the detection of the same attacker-controlled hostname, DESKTOP-BBETH6K, in both incidents raises the suspicion that a single operator or affiliate is orchestrating these attacks.
The ramifications for potential ransomware victims are stark. Timothy remarked, “Criminal actors cannot be trusted, and they may resort to deceitful tactics to extract even further extortion payments from their targets.” He concluded that while Ransom Busters may appear to be offering a helping hand, they are likely manipulating the fear and urgency of victims for financial gain. Payment to any criminal operation not only fails to guarantee the deletion of stolen data but often leads to further complications, as these "benefactors" may not have the victims’ best interests at heart.
In an interesting related development, GuidePoint has brought attention to the sustained operations of UNC6671, an adversary-in-the-middle (AitM) group that has been ruthlessly targeting various sectors, especially financial institutions, since April. The group operates under different extortion brands—such as Falcon, Helix, Pink, and Redact—all of which have contributed to over $8 million in payments across 15 Bitcoin wallets. Statistics show an alarming increase in the sophistication of these cybercriminals, as they increasingly engage in targeted attacks on large organizations, often referred to as “big game hunting.”
With a diving interest in hacking and credential theft, UNC6671 employs a custom system called Work Panel that streamlines their operations, setting a new standard in the landscape of cybercrime. The operations are meticulously designed to separate roles within their criminal framework, shielding individuals from the broader scope of the illicit activities being conducted. This organizational structure illustrates a troubling evolution toward a more industrialized space within cybercrime.
As the ransomware landscape continues to shift, new groups, such as Tengu and CRPx0, are emerging, each with their own unique strategies and target demographics. Notably, while some groups target specific regions, others demonstrate a wide net, showcasing the adaptive and changing nature of ransomware threats globally.
Overall, the emergence of Ransom Busters brings to light not only the complexities of the ransomware ecosystem but also emphasizes the importance for organizations to remain vigilant and fortified against all forms of cyber threats. The clear message is that reliance on dubious offers of help from criminal actors can only lead to more jeopardies, reinforcing the age-old adage that if something appears too good to be true, it likely is.
