Kurzfassung
A threat actor calling itself "Ransom Busters" is contacting ransomware victims before attacks become public, claiming it can decrypt files and delete stolen data for $20,000 $60,000. Researchers at GuidePoint Security (GRIT) and...
Wie es funktioniert
A threat actor calling itself "Ransom Busters" is contacting ransomware victims before attacks become public, claiming it can decrypt files and delete stolen data for $20,000 $60,000. Researchers at GuidePoint Security (GRIT) and...
Warnzeichen
- You are contacted about a ransomware attack that has not been publicly disclosed. The "recovery firm" claims access to keys from multiple unrelated RaaS operations. Pressure to pay quickly via direct wire/crypto with no verifiable track record
Was tun
- 1Never engage unsolicited recovery offers
- 2route any contact through your existing incident response firm. Use only vetted, established negotiation providers and ve
Quelle
bleepingcomputer
Quelle geprueft vom Mythos Forensic Team
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/FAQ
Ist Rogue ransomware affiliate poses as recovery firm to steal victim payments ein reales Betrugsmuster?
Ja. Behandeln Sie Nachricht, Anruf oder Zahlungsaufforderung als verdaechtig, bis ein offizieller Kanal sie bestaetigt.
Was sind die ersten Warnzeichen?
You are contacted about a ransomware attack that has not been publicly disclosed. The "recovery firm" claims access to keys from multiple unrelated RaaS operations. Pressure to pay quickly via direct wire/crypto with no verifiable track record
Was sollte ich zuerst tun?
Never engage unsolicited recovery offers; route any contact through your existing incident response firm. Use only vetted, established negotiation providers and ve
Kann LegalAudit meinen Fall pruefen?
Ja. Starten Sie den kostenlosen Chat und fuegen Sie Nachricht, Link, Absender oder Zahlungsdaten ein.