AI Security AI安全 3d ago Updated 3d ago 更新于 3天前 43

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 Ransom Busters 声称已入侵勒索软件服务器,向受害者索要最高 6 万美元

A threat actor calling itself "Ransom Busters" is proactively emailing ransomware victims, claiming to have breached RaaS group servers and offering to delete stolen data for $20,000–$60,000 GuidePoint GRIT analysis reveals striking tool overlaps (SoftPerfect Network Scanner, s5cmd, Remotely RMM) and a shared backdoor account ("Numlock!123") and hostname (DESKTOP-BBETH6K) across incidents, suggesting a single operator rather than a legitimate third party The actor is believed to be a ransomware Ransom Busters 实为勒索软件附属组织,通过入侵 RaaS 平台服务器向受害者二次勒索 $20,000-$60,000 UNC6671 使用自研 Work Panel 控制台实施工业化 AitM 攻击,已骗取超 $800 万赎金 勒索软件生态持续碎片化,2024 年新涌现 Tengu、CRPx0 等 12 个攻击组织 攻击者采用角色分离架构解决内部人员风险,将呼叫者视为可替换的"商品化劳动力"

68
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • A threat actor calling itself "Ransom Busters" is proactively emailing ransomware victims, claiming to have breached RaaS group servers and offering to delete stolen data for $20,000–$60,000
  • GuidePoint GRIT analysis reveals striking tool overlaps (SoftPerfect Network Scanner, s5cmd, Remotely RMM) and a shared backdoor account ("Numlock!123") and hostname (DESKTOP-BBETH6K) across incidents, suggesting a single operator rather than a legitimate third party
  • The actor is believed to be a ransomware affiliate betraying its own criminal partners for financial gain, with no guarantee that payment results in data deletion
  • UNC6671 (Cordial Spider) is running a sustained adversary-in-the-middle operation since April, generating over $8 million across 15 Bitcoin wallets with an average extortion of $600,000
  • UNC6671 operates a custom "Work Panel" console enabling role-based access, B2B API reconnaissance, automated infrastructure provisioning, and real-time credential relay via phishing templates impersonating Okta and Microsoft 365

Why It Matters

This incident highlights the growing sophistication and industrialization of cybercrime operations, where threat actors are not only targeting victims directly but also exploiting the post-breach chaos through deceptive intermediary schemes. For AI and cybersecurity practitioners, it underscores the importance of verifying the provenance of unsolicited recovery offers and treating them as potential secondary extortion vectors. The evolution of criminal infrastructure—such as UNC6671's role-separated operational model—demonstrates how threat groups are adopting enterprise-grade organizational structures to mitigate insider risk and scale operations.

Technical Details

  • Ransom Busters TTPs: Uses SoftPerfect Network Scanner for internal reconnaissance, s5cmd for data exfiltration to AWS cloud storage, and the Remotely RMM tool installed via PowerShell scripts; creates local backdoor accounts with the password "Numlock!123" and operates from the hostname DESKTOP-BBETH6K
  • UNC6671 Work Panel: A custom console providing role-based access control (callers see only target phone numbers, managers see live session queues, admins own infrastructure), integrated B2B data API reconnaissance, automated infrastructure provisioning, and real-time credential relay management using phishing templates impersonating Okta and Microsoft 365 identity providers
  • Targeting scope: 78 unique phishing sub-domains across 76 organizations in 15 industry sectors, with 40% targeting financial services (hedge funds, venture capital, private equity, asset management)
  • Extortion brands: UNC6671 operates under multiple personas including Falcon, Helix, Pink, Redact, and BlackFile, collecting payments across 15 Bitcoin wallets
  • Ransomware landscape: Proliferation of new groups in recent months including Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova

Industry Insight

  • Organizations should treat unsolicited post-incident recovery offers from unknown parties as high-probability secondary extortion attempts; establish verified communication channels and involve incident response teams before engaging any third party claiming to have breached attacker infrastructure
  • The industrialization of criminal operations—evidenced by UNC6671's role-separated Work Panel and commodity labor model—signals that threat groups are adopting enterprise security practices internally, making detection and attribution increasingly critical for defenders
  • The shift toward "big game hunting" with purposeful, SaaS-centric targeting (as seen with UNC6671 and Shiny Hunters) suggests defenders should prioritize hardening identity infrastructure, implementing MFA enforcement, and monitoring for adversary-in-the-middle activity rather than relying solely on perimeter defenses

TL;DR

  • Ransom Busters 实为勒索软件附属组织,通过入侵 RaaS 平台服务器向受害者二次勒索 $20,000-$60,000
  • UNC6671 使用自研 Work Panel 控制台实施工业化 AitM 攻击,已骗取超 $800 万赎金
  • 勒索软件生态持续碎片化,2024 年新涌现 Tengu、CRPx0 等 12 个攻击组织
  • 攻击者采用角色分离架构解决内部人员风险,将呼叫者视为可替换的"商品化劳动力"

为什么值得看

本文揭示了勒索软件攻击从单纯加密勒索向"数据窃取+二次勒索"复合模式的演进,以及攻击基础设施的工业化趋势。对安全从业者而言,UNC6671 的 Work Panel 控制台展示了 AitM 攻击的新范式,其角色分离设计值得防御方重点关注。

技术解析

  • Work Panel 控制台:UNC6671 自研的 AitM 攻击平台,支持 RBAC 权限分离、商业 B2B 数据 API 集成侦察、自动化基础设施部署及实时凭证中继管理
  • 攻击工具链:使用 SoftPerfect Network Scanner 进行内网侦察,s5cmd 通过 AWS 云存储外泄数据,Remotely RMM 工具通过 PowerShell 脚本部署
  • 后门特征:创建本地后门账户使用固定密码"Numlock!123",攻击者控制主机名 DESKTOP-BBETH6K 在多个事件中重复出现
  • 组织架构:呼叫者仅知目标电话号码,经理可见实时会话队列,管理员掌控基础设施,实现严格的职责分离
  • 目标行业分布:78 个钓鱼子域名覆盖 76 家机构,40% 为对冲基金、风投、私募股权等金融机构

行业启示

  • 勒索软件攻击正从"机会主义加密"转向"针对性数据勒索",防御策略需从单纯恢复转向数据泄露预防
  • 攻击基础设施的工业化(如 Work Panel)表明黑产已形成完整产业链,建议企业加强身份验证系统的多因素防护
  • 面对"第三方救援"类诈骗,组织应建立官方应急响应渠道,避免向非授权方支付赎金导致二次损失

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究