A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model.
According to the GuidePoint Research and Intelligence Team (GRIT), a malicious entity referring to itself as "Ransom Busters" has sent an email to cyberattack victims, claiming to have infiltrated the servers of multiple criminal groups and discovering data belonging to the victim. For a fee, the email claims, Ransom Busters "can return your files to you and destroy all backups held by the group." The email claims the attackers have also gained access to encryption keys that can be used to help victims access their files.
"We observed this behavior while responding to incidents from threat groups including DragonForce, Settra, and Anubis," according to the blog post, released today. "The threat actor claimed this access allowed them control over 'almost all of their infrastructure. Like [ransomware as a service [RaaS] groups, Ransom Busters' motivation appears to be financial. Ransom Busters confirmed access to the exact same dataset that the ransomware affiliate possessed, when questioned. The group offered to delete the victim's stolen data from the ransomware groups' servers for a fee of between $20,000 to $60,000."
Ransom Busters' Red Flags
There are multiple red flags behind the purported offer of help, as Justin Timothy, principal threat intelligence consultant at GuidePoint Security, explained in the blog post. For one, in the cases GRIT observed, Ransom Busters reached out before the ransomware attack became public knowledge; incident-response firms usually offer their services after an attack is disclosed.
Ransom Busters also claims in its communications to have accessed the administrative panel of ransomware-as-a-service (RaaS) actors. Offensive actions from a third party, Timothy noted, could be considered a violation of the US government's Computer Fraud Abuse Act.
"We would not expect a legitimate organization to potentially commit a crime, much less to charge a fee in exchange for doing so," Timothy wrote.
GuidePoint's Digital Forensics and Incident Response (DFIR) team responded to two incidents where Ransom Busters contacted victims, and in both cases, the intrusions were notably similar (as Timothy wrote, while many intrusions share similar elements, "each attack typically has its own unique characteristics in terms of tooling used and persistence mechanisms within the victim’s network"). There were overlaps in the tools used for internal reconnaissance, data exfiltration, and remote monitoring and management (RMM). The local backdoor accounts also shared a password, and the same attacker-controlled hostname was identified across attacks.