Ransom Busters Claims It Hacked Ransomware Servers – Veri Sızıntısı

Ransom Busters Claims It Hacked Ransomware Servers

A group calling itself "Ransom Busters" is contacting victims of ransomware attacks, claiming they have hacked the attackers' servers and can delete stolen data for fees up to $60,000. Experts warn this is a scam by the attackers themselves.

A computer screen showing a ransomware warning message in front of a hooded silhouette of a hacker.

What Happened

In an unusual tactic within the cybercrime world, a group calling itself "Ransom Busters" has been proactively sending emails to companies victimized by ransomware. In these messages, the group claims to have infiltrated the servers of ransomware gangs and offers to delete the company's stolen data in exchange for a fee. The demanded fees for this "service" range from $20,000 to $60,000.

This situation was detailed in a report shared by the cybersecurity firm GuidePoint Research and Intelligence Team (GRIT). "In these messages, the third-party offers to help the victim recover from a ransomware attack. This immediately stands out as anomalous," GRIT explained. Typically, cybersecurity firms contact victims to offer consulting or recovery services only after an attack becomes public knowledge. However, Ransom Busters' proactive and secretive approach signals that it is not a legitimate operation.

GRIT stated that it has responded to several ransomware incidents involving this actor, who is believed to be an affiliate with employment across multiple Ransomware-as-a-Service (RaaS) operations. In emails sent to victims, Ransom Busters requests contact with their CEO or IT leadership. They claim in their messages to have found vulnerabilities in administrative panels maintained by RaaS groups and to have been breaking into these servers for over three years.

The Data Seized

According to Ransom Busters' claim, they found data stolen from the victim company on one of the servers they recently accessed. The group demands a payment in exchange for the complete deletion of this data, including all backups held by the ransomware gang. This opens a second door for extortion for victim companies. After first facing a ransom demand from the ransomware gang for their encrypted files, companies are now confronted with another payment request with the promise of complete data deletion. However, experts issue a clear warning that this promise comes with no guarantees. While no specific information about the content or volume of the stolen data is provided, the threat actor's goal is to capitalize on the victim's fear of a data leak to secure an additional profit.

How the Attack Unfolded

GuidePoint's analysis strengthens suspicions that a single operator, most likely a ransomware affiliate, is behind the Ransom Busters identity. Researchers who examined two separate incidents where Ransom Busters contacted victims found "striking" similarities in both attacks. This technical evidence indicates that the event was not carried out by an independent "white hat" hacker group but is a deception orchestrated by the same attacker.

The common techniques and tools identified include:

  • SoftPerfect Network Scanner: The attacker used this tool for internal reconnaissance to discover other systems within the company network.
  • s5cmd: This command-line tool was preferred for exfiltrating stolen data to cloud storage via AWS.
  • Remotely: This remote monitoring and management (RMM) tool, installed via a PowerShell script, allowed the attacker to maintain persistent access to the system.

In addition to these tools, it was observed that in both incidents, the attacker created a local backdoor account using the password "Numlock!123" and the same attacker-controlled hostname, "DESKTOP-BBETH6K," was detected. These consistencies strongly support the theory that the activity is the work of one of the ransomware affiliates, rather than a third party.

Who Is Affected

GuidePoint noted that this modus operandi was observed while responding to ransomware incidents involving threat groups such as DragonForce, Settra, and Anubis. This suggests that Ransom Busters could be an affiliate who works with these specific groups or somehow has access to their infrastructure. Therefore, any organization of any size or in any sector targeted by these groups could potentially receive similar deceptive offers from Ransom Busters.

What You Can Do

Experts stress that victims of ransomware must be extremely cautious about offers from actors like Ransom Busters. Here are the steps to take:

  • Treat the Offer as a Hoax: Such offers are most likely a tactic used by the original attackers to extort more money. These groups, masquerading as "beneficent saviors," should not be trusted under any circumstances.
  • Do Not Pay: Paying either the original ransom demand or the fee for the promise of data deletion does not guarantee that your data will be deleted or returned. Paying criminals generally encourages more attacks and offers no assurance.
  • Cease Communication: If you receive an email from Ransom Busters or a similar group, do not engage with them. Any form of communication can make you vulnerable to further manipulation.
  • Get Professional Help: If you have been hit by a ransomware attack, immediately contact a legitimate cybersecurity and incident response firm. These firms can help you assess the damage, recover your systems, and notify legal authorities.

What the Experts Say

Justin Timothy, a Principal Consultant at GRIT, sums up the situation clearly: "The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments." Timothy adds that 'Ransom Busters,' or more likely, the ransomware affiliate maintaining this persona, has shown it will betray even its own criminal partners in pursuit of financial gain.

GuidePoint also states that the possibility of such an act being carried out by a legitimate organization is extremely unlikely, as it would amount to a violation of the U.S. Computer Fraud Abuse Act. The group's puzzling explanation when asked why they charged for their help—that "acting without compensation would put their access to the threat actor's infrastructure at risk"—also raises suspicion. Timothy's final words are a warning: "Payment to any criminal party offers no guarantee that stolen data will be deleted. There are no 'magic bullets' for remedying data exfiltration and 'Ransom Busters' masquerading as beneficent saviors should be treated as a hoax."

Source

https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.