'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
Summary
A ransomware affiliate has been observed posing as an incident-recovery service, offering assistance to victims. This tactic is intended to trick victims into diverting their ransom payments to the threat actor.
IFF Assessment
FOE
This describes a new tactic by ransomware actors to deceive victims, making it harder to recover and potentially increasing the success rate of their attacks.
Defender Context
Defenders should be aware of this deceptive tactic where ransomware groups masquerade as legitimate recovery services. It's crucial to verify the identity of any 'recovery' assistance and avoid sharing sensitive information or making payments to unverified entities, as this could lead to further compromise or loss.