Listen to the episode
TLDR
A threat actor calling itself "Ransom Busters" is contacting ransomware victims before attacks become public, claiming it can decrypt files and delete stolen data for $20,000 $60,000. Researchers at GuidePoint Security (GRIT) and...
How it works
A threat actor calling itself "Ransom Busters" is contacting ransomware victims before attacks become public, claiming it can decrypt files and delete stolen data for $20,000 $60,000. Researchers at GuidePoint Security (GRIT) and...
Red flags
- You are contacted about a ransomware attack that has not been publicly disclosed. The "recovery firm" claims access to keys from multiple unrelated RaaS operations. Pressure to pay quickly via direct wire/crypto with no verifiable track record
What to do
- 1Never engage unsolicited recovery offers
- 2route any contact through your existing incident response firm. Use only vetted, established negotiation providers and ve
Source
bleepingcomputer
Source reviewed by Mythos Forensic Team
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/FAQ
Is Rogue ransomware affiliate poses as recovery firm to steal victim payments a real scam pattern?
Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.
What are the first warning signs?
You are contacted about a ransomware attack that has not been publicly disclosed. The "recovery firm" claims access to keys from multiple unrelated RaaS operations. Pressure to pay quickly via direct wire/crypto with no verifiable track record
What should I do first?
Never engage unsolicited recovery offers; route any contact through your existing incident response firm. Use only vetted, established negotiation providers and ve
Can LegalAudit check my case?
Yes. Start a free chat and paste the message, link, sender, or payment details for triage.