Beware the Ransomware Rescuer: Ransom Busters

BLOG

The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous. While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge. This ostensible third-party’s insight into an attack that was not yet public is alarming. It raises the question how “Ransom Busters” could know about the incident at all.

TL;DR – As the saying goes, if it’s too good to be true, it probably is. Ransom Busters has been proactively reaching out to companies alerting them to incidents before knowledge is made public.

  • Cybersecurity firms usually only reach out once an attack becomes public
  • GRIT assesses Ransom Busters to be a ransomware affiliate
  • This organization is employing a new extortion technique; GRIT urges caution

 

As part of incident response efforts, GRIT communicated with this new entity to answer a central question: is “Ransom Busters” a genuinely benevolent third party working against ransomware groups? Or is it something malicious? 

Based on our findings, GRIT assesses that Ransom Busters is a ransomware affiliate working across several ransomware operations, who has simply resorted to an alternate extortion technique. 

Ransom Busters

It started when several victim organizations were contacted via emails from “Ransom Busters LTD” sent to domain email addresses. Those email requested contact with the victim’s CEO or IT leadership. The email sent to multiple victims all included the following:

I am a representative of a project that assists victims of cyberattacks. We have been identifying vulnerabilities and infiltrating the servers of criminal groups for over three years. On the server we recently accessed, we discovered data stolen from your company [...] We can return your files to you and destroy all backups held by the group. Additionally, we have gained access to the encryption key storage and can help you regain access to your encrypted files.

In the communications that followed, the actor claimed to have discovered vulnerabilities in the “administrative panels” (the backend of the threat actor’s ransomware operations portal) of several ransomware-as-a-service (RaaS) operations. 

We observed this behavior while responding to incidents from threat groups including DragonForce, Settra and Anubis. The threat actor claimed this access allowed them control over “almost all of their infrastructure.” Like RaaS groups, Ransom Busters’ motivation appears to be financial. Ransom Busters confirmed access to the exact same dataset that the ransomware affiliate possessed, when questioned. The group offered to delete the victim’s stolen data from the ransomware groups’ servers for a fee of between $20,000 to $60,000.  

Notably, the kind of offensive actions claimed by this third-party, such as unauthorized access to a RaaS operation’s servers to delete data, could be considered a violation of the Computer Fraud Abuse Act

We would not expect a legitimate organization to potentially commit a crime, much less to charge a fee in exchange for doing so. This suggests that the operators were very likely either obfuscating the true origin of their access or they were not operating within the confines of the law. When pressed on why they charged for their help, the group offered a puzzling explanation: that acting without compensation would put their access to the threat actor’s infrastructure at risk. Paying this group would have no logical bearing on their ability to access criminal infrastructure, making this a difficult explanation to accept.

Recently, GuidePoint’s DFIR (Digital Forensics and Incident Response) team responded to two incidents where Ransom Busters contacted victims. Upon analyzing the cases, GRIT (part of the DFIR team) discovered striking similarities. While most ransomware intrusions follow similar playbooks, each attack typically has its own unique characteristics in terms of tooling used and persistence mechanisms within the victim’s network. Forensic analysis of both environments revealed overlaps in the tools used, including SoftPerfect Network Scanner for internal reconnaissance, the s5cmd tool for exfiltrating data to cloud storage via AWS and the Remotely remote monitoring and management (RMM) tool installed through a PowerShell script. Threat actors maintain several options available to perform all of these tasks, so the use of identical tools in multiple environments suggest the same operator enacting the intrusions. Both cases also showed that the threat actor created a local backdoor account using the same password of Numlock!123. Since password choice is essentially unconstrained, using the same one is a strong point of correlation between the cases. Furthermore, the same attacker-controlled hostname, DESKTOP-BBETH6K, was identified across both intrusions. 

While these overlaps in tooling, techniques and host machines could simply be a shared playbook and possibly a standardized virtual machine environment distributed to multiple affiliates within the same RaaS operation, we consider this explanation to be less plausible. GuidePoint has observed the overlap in activity across several distinct RaaS programs where “Ransom Busters” has intervened. That supports our assessment that this is not a genuine third-party researcher, but rather a single ransomware affiliate enacting the same set of Tactics, Techniques and Procedures (TTPs) across multiple victims’ environments.

Conclusion

GRIT assesses with moderate confidence that “Ransom Busters” is not a bona fide third-party victim services firm, but rather a single ransomware affiliate with employment across multiple RaaS operations, using their affiliate access to divert ransom payment discussions away from the original ransomware operation.

The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments. “Ransom Busters” or, more likely, the ransomware affiliate maintaining this persona, has shown it will betray even its own criminal partners in pursuit of financial gain. 

Payment to any criminal party offers no guarantee that stolen data will be deleted. In other cases, researchers have observed evidence of threat actors retaining multiple copies of stolen data that may later be sold or used for re-extortion. There are no “magic bullets” for remedying data exfiltration and “Ransom Busters’” masquerading as beneficent saviors should be treated as a hoax. 

Victims who receive this type of contact should report it to their incident response team immediately. Law enforcement and reputable incident response firms remain the most reliable resources when navigating a ransomware incident and any unsolicited offer to “help” for a fee should be treated with significant skepticism.

Justin Timothy is a Principal Consultant on GuidePoint Security’s Research and Intelligence Team (GRIT), where he focuses on threat intelligence research, incident response investigations and reporting to support clients across various industry verticals. Before joining GuidePoint, Justin worked on the Malware and Cyber Threats team at the National Cyber-Forensics and Training Alliance. While there, he focused on threat intelligence collections, malware analysis and supporting clients’ cyber threat intelligence teams. Justin holds a Bachelor of Science in Computer Science from Seton Hill University.