HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Ransomware Affiliate Masquerades as Recovery Service to Steal Victim Payments

A ransomware‑as‑a‑service affiliate is posing as a recovery firm called “Ransom Busters,” contacting victims before public disclosure and demanding $20‑$60 K for decryption keys. The activity highlights the need for SOC 2‑aligned security‑awareness training and verification controls to prevent BEC‑style extortion.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
Medium
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Rogue Ransomware Affiliate Masquerades as “Ransom Busters” to Steal Victim Payments

What Happened — A ransomware‑as‑a‑service (RaaS) affiliate is contacting victims before the attacks become public, posing as a recovery firm called “Ransom Busters.” The group claims it can provide decryption keys and delete stolen data for a fee of $20‑$60 K, but evidence suggests it is the same affiliate that ran the original ransomware campaign and is now trying to siphon ransom payments.

Why It Matters for Compliance & Audit Readiness

  • The tactic is a classic business‑email‑compromise (BEC) scenario that tests an organization’s access‑control policies, incident‑response verification steps, and employee awareness—core SOC 2 CC6 and CC7 controls.
  • Continuous evidence of security‑awareness training and documented verification of third‑party recovery services provides auditors with a defensible trail that the organization mitigates social‑engineering risk.
  • Verisq’s Security Awareness capability can supply audit‑ready training records, phishing‑simulation results, and policy adoption metrics to satisfy SOC 2 evidence requirements.

Who Is Affected — Enterprises across all verticals that have been targeted by ransomware (healthcare, finance, manufacturing, SaaS, etc.).

Recommended Actions

  • Update your incident‑response playbook to require independent verification of any recovery‑service outreach (e.g., out‑of‑band confirmation, digital signatures).
  • Enforce multi‑factor authentication (MFA) on all privileged accounts and monitor for creation of anomalous local admin accounts (e.g., “Numlock!123”).
  • Conduct targeted security‑awareness training on ransomware‑recovery scams and BEC tactics; capture completion data for audit evidence.
  • Log and review all inbound emails that reference decryption or data‑deletion services; flag any that arrive before public disclosure of an incident.

Source: BleepingComputer

Technical Notes

  • Attackers leveraged common tools: SoftPerfect Network Scanner, s5cmd, and the Remotely RMM agent.
  • They created a persistent backdoor local account with the password “Numlock!123” and used a consistent hostname “DESKTOP‑BBETH6K.”
  • No evidence of data leakage beyond the RaaS environment; the primary goal appears to be financial extortion.
📰 Original Source
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →