Security
Researchers link fake recovery service to ransomware affiliate
Image: Primary GuidePoint Security's GRIT says a suspected ransomware affiliate has posed as a recovery service called Ransom Busters, contacting victims before attacks became public and offering decryption keys and data deletion for $20,000 to $60,000. GRIT found overlapping tools, tactics, a backdoor account password and an attacker-controlled hostname in two incidents, leading it to assess with moderate confidence that a single affiliate was seeking payments outside ransomware-as-a-service revenue sharing. Coveware confirmed handling at least one similar incident.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire