Rogue ransomware affiliate poses as data recovery firm to steal payments

Summary

A ransomware affiliate is posing as a data recovery firm called "Ransom Busters." This actor contacts ransomware victims before their attacks are publicly disclosed, offering to provide decryption keys and delete stolen data for a fee. This tactic aims to profit from victims' distress and lack of immediate information.

IFF Assessment

FOE

This article describes a new tactic used by ransomware affiliates to exploit victims, which directly harms defenders and organizations.

Defender Context

This threat actor's new social engineering approach highlights the importance of verifying any third-party claims for data recovery, especially when dealing with ransomware incidents. Defenders should educate their teams and potentially incident response partners about this specific tactic to avoid falling victim to further exploitation after a breach.

Read Full Story →