Rogue Ransomware Affiliate Masquerades as “Ransom Busters” to Steal Victim Payments
What Happened — A ransomware‑as‑a‑service (RaaS) affiliate is contacting victims before the attacks become public, posing as a recovery firm called “Ransom Busters.” The group claims it can provide decryption keys and delete stolen data for a fee of $20‑$60 K, but evidence suggests it is the same affiliate that ran the original ransomware campaign and is now trying to siphon ransom payments.
Why It Matters for Compliance & Audit Readiness
- The tactic is a classic business‑email‑compromise (BEC) scenario that tests an organization’s access‑control policies, incident‑response verification steps, and employee awareness—core SOC 2 CC6 and CC7 controls.
- Continuous evidence of security‑awareness training and documented verification of third‑party recovery services provides auditors with a defensible trail that the organization mitigates social‑engineering risk.
- Verisq’s Security Awareness capability can supply audit‑ready training records, phishing‑simulation results, and policy adoption metrics to satisfy SOC 2 evidence requirements.
Who Is Affected — Enterprises across all verticals that have been targeted by ransomware (healthcare, finance, manufacturing, SaaS, etc.).
Recommended Actions
- Update your incident‑response playbook to require independent verification of any recovery‑service outreach (e.g., out‑of‑band confirmation, digital signatures).
- Enforce multi‑factor authentication (MFA) on all privileged accounts and monitor for creation of anomalous local admin accounts (e.g., “Numlock!123”).
- Conduct targeted security‑awareness training on ransomware‑recovery scams and BEC tactics; capture completion data for audit evidence.
- Log and review all inbound emails that reference decryption or data‑deletion services; flag any that arrive before public disclosure of an incident.
Source: BleepingComputer
Technical Notes
- Attackers leveraged common tools: SoftPerfect Network Scanner, s5cmd, and the Remotely RMM agent.
- They created a persistent backdoor local account with the password “Numlock!123” and used a consistent hostname “DESKTOP‑BBETH6K.”
- No evidence of data leakage beyond the RaaS environment; the primary goal appears to be financial extortion.