A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model.
According to the GuidePoint Research and Intelligence Team (GRIT), a malicious entity referring to itself as “Ransom Busters” has sent an email to cyberattack victims, claiming to have infiltrated the servers of multiple criminal groups and discovering data belonging to the victim. For a fee, the email claims, Ransom Busters “can return your files to you and destroy all backups held by the group.” The email claims the attackers have also gained access to encryption keys that can be used to help victims access their files.
“We observed this behavior while responding to incidents from threat groups including DragonForce, Settra, and Anubis,” according to the blog post, released today. “The threat actor claimed this access allowed them control over ‘almost all of their infrastructure. Like [ransomware as a service [RaaS] groups, Ransom Busters’ motivation appears to be financial. Ransom Busters confirmed access to the exact same dataset that the ransomware affiliate possessed, when questioned. The group offered to delete the victim’s stolen data from the ransomware groups’ servers for a fee of between $20,000 to $60,000.”
Ransom Busters’ Red Flags
There are multiple red flags behind the purported offer of help, as Justin Timothy, principal threat intelligence consultant at GuidePoint Security, explained in the blog post. For one, in the cases GRIT observed, Ransom Busters reached out before the ransomware attack became public knowledge; incident-response firms usually offer their services after an attack is disclosed.
Ransom Busters also claims in its communications to have accessed the administrative panel of ransomware-as-a-service (RaaS) actors. Offensive actions from a third party, Timothy noted, could be considered a violation of the US government’s Computer Fraud Abuse Act.
“We would not expect a legitimate organization to potentially commit a crime, much less to charge a fee in exchange for doing so,” Timothy wrote.
GuidePoint’s Digital Forensics and Incident Response (DFIR) team responded to two incidents where Ransom Busters contacted victims, and in both cases, the intrusions were notably similar (as Timothy wrote, while many intrusions share similar elements, “each attack typically has its own unique characteristics in terms of tooling used and persistence mechanisms within the victim’s network”). There were overlaps in the tools used for internal reconnaissance, data exfiltration, and remote monitoring and management (RMM). The local backdoor accounts also shared a password, and the same attacker-controlled hostname was identified across attacks.
GRIT ultimately assessed with moderate confidence that Ransom Busters is not a true third-party researcher, but rather a single ransomware affiliate that works with multiple RaaS actors and implements the same tactics across victim environments. The ultimate goal of this, GRIT believes, is that Ransom Busters is “using their affiliate access to divert ransom payment discussions away from the original ransomware operation.”
In many RaaS operations, affiliates do not have unilateral control over every copy of stolen data or the broader extortion infrastructure. As a result, victims have little ability to verify claims that data has actually been deleted or that all parties with access to the information have relinquished it.
GRIT believes the activity may represent an attempt by an affiliate to monetize victims outside the traditional RaaS payment structure, potentially diverting revenue away from the ransomware operation itself.
Don’t Get Busted by the Busters
Timothy tells Dark Reading that Ransom Busters’ tactics actually undermine the core RaaS business model.
“A standard part of ransom negotiations involves the threat actor’s commitment to delete exfiltrated data upon payment. If both the RaaS operation and Ransom Busters retain copies of the stolen data, victims have no reasonable assurance that all copies will be destroyed,” he says. “That alone can make any payment for data suppression effectively worthless. From a financial standpoint, Ransom Busters’ activity directly damages the credibility and revenue potential of the RaaS operations they are affiliated with.”
Although he is not aware of a case where these tactics have succeeded, Timothy stresses that a contact made from a non-law enforcement entity mid-incident is very unusual. Legitimate outreach typically comes from a corporate email domain and not a free or privacy-focused service like ProtonMail (Ransom Busters used a privacy-focused email address with no verifiable domain, he adds).
“Legitimate IR firms also do not provide pricing before an initial scoping call. They need to understand the incident before quoting anything. Ransom Busters, by contrast, introduced a financial demand early in communications, closely mirroring the behavior of actual ransomware actors,” Timothy says. “Finally, no credible cybersecurity vendor requests payment in Bitcoin. That alone should be treated as a strong indicator of malicious intent.”


