Dark Reading reports:
A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model.
According to the GuidePoint Research and Intelligence Team (GRIT), a malicious entity referring to itself as “Ransom Busters” has sent an email to cyberattack victims, claiming to have infiltrated the servers of multiple criminal groups and discovering data belonging to the victim. For a fee, the email claims, Ransom Busters “can return your files to you and destroy all backups held by the group.” The email claims the attackers have also gained access to encryption keys that can be used to help victims access their files.
“We observed this behavior while responding to incidents from threat groups including DragonForce, Settra, and Anubis,” according to the blog post, released today. “
Read more at Dark Reading.
