news.mlab.sh
Back to the feed
threat-intel

'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service

High
Image: Dark Reading
Summary

A ransomware affiliate, calling itself ‘Ransom Busters,’ is attempting to undermine the RaaS business model by contacting victims of ransomware attacks and offering to retrieve their stolen data and destroy backups for a fee. GuidePoint Research and Intelligence Team (GRIT) has identified this tactic as a deceptive attempt to divert ransom payments away from the original ransomware operation, and has noted that the affiliate’s actions create a lack of assurance that all copies of stolen data will be deleted, rendering payments for data suppression ineffective. The group’s behavior is unusual, mimicking ransomware actors by offering a price upfront and using privacy-focused email addresses, a tactic not typically employed by legitimate incident response firms.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.