The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous. While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge. This ostensible third-party’s insight into an attack that was not yet public is alarming. It raises the question how “Ransom Busters” could know about the incident at all.
Justin Timothy is a Principal Consultant on GuidePoint Security’s Research and Intelligence Team (GRIT), where he focuses on threat intelligence research, incident response investigations and reporting to support clients across various industry verticals. Before joining GuidePoint, Justin worked on the Malware and Cyber Threats team at the National Cyber-Forensics and Training Alliance. While there, he focused on threat intelligence collections, malware analysis and supporting clients’ cyber threat intelligence teams. Justin holds a Bachelor of Science in Computer Science from Seton Hill University.