Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: Medium
Victim: Organizations previously targeted by RaaS groups
Incident: A threat actor is posing as a recovery service to extort victims of ransomware attacks.
Impact: Financial loss and potential further data exposure through deceptive ‘recovery’ schemes.
Attacker: Ransom Busters
Analysis: Ransom Busters is employing a deceptive social engineering tactic by claiming to have infiltrated RaaS servers to ‘recover’ stolen data for a fee. Technical evidence, including the use of SoftPerfect Network Scanner and a specific local backdoor password, suggests the operator is likely a ransomware affiliate rather than a legitimate entity. This represents a secondary extortion trend where criminals prey on the desperation of existing victims.
Recommendations: Avoid engaging with unauthorized third parties claiming to possess stolen data; Verify all recovery and negotiation services through licensed, reputable cybersecurity firms; Audit local accounts for unauthorized backdoors and rotate credentials following an incident
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source