Rogue ransomware affiliate poses as recovery firm to steal payments

Summary

A ransomware affiliate is impersonating a ransomware recovery firm named "Ransom Busters." This actor contacts victims before attacks are public, offering to decrypt files and delete stolen data for a fee. The group appears to be operating independently and not associated with any known ransomware families.

IFF Assessment

FOE

This actor is exploiting ransomware victims by posing as a legitimate recovery service, exacerbating the damage caused by the initial attack and defrauding victims.

Defender Context

Defenders should be aware of social engineering tactics used by ransomware affiliates, including impersonation of recovery services. This highlights the need for robust incident response plans that verify the identity of any third parties claiming to assist victims and educate employees about potential scams.

Read Full Story →