DragonForce and Settra: Rogue ransomware affiliate poses as data recovery firm to steal payments

DragonForce and Settra: Rogue ransomware affiliate poses as data recovery firm to steal payments

Ransomware Affiliate Masquerades as Recovery Service in Sophisticated Extortion Scheme

A suspected ransomware affiliate is targeting victims under the guise of a recovery service called Ransom Busters, contacting them before attacks become public and offering decryption keys and data deletion for a fee. GuidePoint Security’s Research and Intelligence Team (GRIT) uncovered the scheme after responding to multiple ransomware incidents where victims received unsolicited emails from the group.

Ransom Busters claimed to exploit vulnerabilities in ransomware-as-a-service (RaaS) administrative panels, granting access to encryption keys and stolen data from operations like DragonForce, Settra, and Anubis. The group demanded payments between $20,000 and $60,000 to delete data from ransomware servers. However, GRIT’s investigation revealed strong evidence linking Ransom Busters to the attacks themselves. In two incidents, the same tools (SoftPerfect Network Scanner, s5cmd, Remotely), tactics (including a backdoor account with the password Numlock!123), and attacker-controlled hostname (DESKTOP-BBETH6K) were used.

GRIT concluded with moderate confidence that Ransom Busters is a single ransomware affiliate attempting to divert ransom payments from RaaS gangs. While no victims have reportedly paid the group, one victim instead paid the RaaS operation behind the attack yet their data was not leaked, suggesting Ransom Busters may have complied with the agreement.

Ransomware negotiation firm Coveware confirmed encountering similar activity, noting this behavior differs from typical "ambulance chasers" who target publicly disclosed victims. Unlike those opportunists, Ransom Busters exploits non-public incidents, increasing risks for victims paying the ransom may no longer guarantee data deletion if multiple parties have access. Coveware warned that growing distrust within RaaS ecosystems could fuel more such schemes as affiliates seek additional profits outside standard revenue-sharing models.

The incident highlights an alarming evolution in ransomware tactics, where attackers not only encrypt data but also pose as recovery services to exploit victims before breaches are detected.

Source: https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/

Proven Data cybersecurity rating report: https://www.rankiteo.com/company/provendata

DragonForce cybersecurity rating report: https://www.rankiteo.com/company/dragonforce

"id": "PRODRA1787174209",
"linkid": "provendata, dragonforce",
"type": "Ransomware",
"date": "1/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'attack_vector': 'Exploitation of RaaS administrative panels, '
                  'phishing/unsolicited emails',
 'customer_advisories': 'Be cautious of unsolicited recovery offers and verify '
                        'the legitimacy of third-party services before '
                        'engaging.',
 'data_breach': {'data_encryption': 'Yes',
                 'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, proprietary data)',
                 'type_of_data_compromised': ['Encryption keys',
                                              'Stolen data']},
 'description': 'A suspected ransomware affiliate is targeting victims under '
                'the guise of a recovery service called *Ransom Busters*, '
                'contacting them before attacks become public and offering '
                'decryption keys and data deletion for a fee. The group '
                'claimed to exploit vulnerabilities in ransomware-as-a-service '
                '(RaaS) administrative panels, granting access to encryption '
                'keys and stolen data from operations like *DragonForce*, '
                '*Settra*, and *Anubis*. However, investigations revealed '
                'strong evidence linking *Ransom Busters* to the attacks '
                'themselves, suggesting they are a single ransomware affiliate '
                'attempting to divert ransom payments from RaaS gangs.',
 'impact': {'data_compromised': 'Encryption keys, stolen data, personally '
                                'identifiable information',
            'financial_loss': '$20,000 - $60,000 (demanded fees)',
            'identity_theft_risk': 'High'},
 'initial_access_broker': {'backdoors_established': 'Yes (backdoor account '
                                                    'with password '
                                                    '*Numlock!123*)',
                           'entry_point': 'Exploitation of RaaS administrative '
                                          'panels'},
 'investigation_status': 'Ongoing (moderate confidence in findings)',
 'lessons_learned': 'Growing distrust within RaaS ecosystems could fuel more '
                    'such schemes as affiliates seek additional profits. '
                    'Victims paying ransom may no longer guarantee data '
                    'deletion if multiple parties have access.',
 'motivation': 'Financial gain, diversion of ransom payments from RaaS gangs',
 'post_incident_analysis': {'corrective_actions': 'Enhanced monitoring, '
                                                  'verification of recovery '
                                                  'services, and improved '
                                                  'incident response '
                                                  'strategies',
                            'root_causes': 'Exploitation of vulnerabilities in '
                                           'RaaS administrative panels, '
                                           'affiliate-driven extortion '
                                           'schemes'},
 'ransomware': {'data_encryption': 'Yes',
                'data_exfiltration': 'Yes',
                'ransom_demanded': '$20,000 - $60,000',
                'ransom_paid': 'At least one victim paid the RaaS operation '
                               '(amount undisclosed)',
                'ransomware_strain': ['DragonForce', 'Settra', 'Anubis']},
 'recommendations': 'Enhanced monitoring for unsolicited recovery offers, '
                    'verification of third-party recovery services, and '
                    'improved incident response planning to address evolving '
                    'ransomware tactics.',
 'references': [{'source': 'GuidePoint Security’s Research and Intelligence '
                           'Team (GRIT)'},
                {'source': 'Coveware'}],
 'response': {'third_party_assistance': 'GuidePoint Security’s Research and '
                                        'Intelligence Team (GRIT), Coveware'},
 'stakeholder_advisories': 'Ransomware affiliates may pose as recovery '
                           'services to exploit victims before breaches are '
                           'detected. Paying ransom does not guarantee data '
                           'deletion if multiple parties are involved.',
 'threat_actor': 'Ransom Busters (suspected ransomware affiliate)',
 'title': 'Ransomware Affiliate Masquerades as Recovery Service in '
          'Sophisticated Extortion Scheme',
 'type': 'Ransomware',
 'vulnerability_exploited': 'Vulnerabilities in RaaS administrative panels'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.