Ransomware Affiliate Poses As Fake 'Ransom Busters' Recovery Firm
A threat actor operating under the name "Ransom Busters" is contacting ransomware victims directly, posing as an independent recovery service that can delete stolen data and provide decryption keys in exchange for payment. Security researchers now believe the entity is not a legitimate third party at all, but a rogue ransomware affiliate exploiting insider access to divert ransom payments away from the criminal groups it works with.

The scheme was first documented by GuidePoint Security's Research and Intelligence Team (GRIT), which encountered the activity while responding to several ransomware incidents. Victims reported receiving unsolicited emails from "Ransom Busters LTD" requesting contact with company executives or IT leadership well before the underlying ransomware attacks were publicly disclosed.
Legitimate cybersecurity firms and self-styled "recovery" operators typically reach out to ransomware victims only after an attack has already surfaced on a leak site or in the press. Ransom Busters' emails arrived earlier than that, prompting researchers to question how the group could have known about non-public incidents at all.
According to GRIT, the messages claimed the sender had spent years infiltrating the infrastructure used by ransomware-as-a-service (RaaS) operations and had discovered vulnerabilities in the "administrative panels" used by affiliates to manage their attacks. Ransom Busters told victims that they could use this access to erase stolen files from criminal servers and unlock encrypted data.
One email reviewed by researchers stated that the group could return victims' files and destroy all backups it held, and offered help with decryption. The group set its price for these services between 20,000 USD and 60,000 USD, and claimed the fee was necessary to protect its ongoing access to the criminal infrastructure it said it had compromised.
Researchers noted that the conduct described, unauthorized intrusion into another party's servers, would itself amount to a crime, making it unlikely that a genuine, law-abiding recovery service would market itself this way, let alone charge money for it.
Technical Overlaps Point to a Single Affiliate
GuidePoint's Digital Forensics and Incident Response (DFIR) team examined two separate ransomware cases in which Ransom Busters had contacted the victim and found the underlying intrusions shared unusually specific characteristics. Both attacks involved the same set of tools, including SoftPerfect Network Scanner for internal network reconnaissance, the s5cmd utility for exfiltrating stolen data to cloud storage, and the Remotely remote monitoring and management tool, deployed through a PowerShell script.
Investigators also found that both intrusions used an identical local backdoor account password, "Numlock!123," and the same attacker-controlled hostname, "DESKTOP-BBETH6K." Because such details are typically unique to individual affiliates or campaigns, the overlap led researchers to conclude the attacks were carried out by the same operator rather than independent actors following a shared criminal playbook.
GRIT reported observing this pattern of behavior across multiple, unrelated RaaS brands, including DragonForce, Settra, and Anubis. Based on that pattern, the team assessed with moderate confidence that Ransom Busters is a single ransomware affiliate working across several RaaS programs, using its privileged access to intercept and redirect ransom negotiations for personal profit, effectively defrauding the very criminal organizations it partners with.
GRIT told BleepingComputer it has not observed any victim actually pay Ransom Busters and advises against doing so. In one documented case, the targeted organization instead paid the original ransomware operation rather than the impersonator; researchers found no evidence that the stolen data from that incident was later published on the RaaS group's leak site or leaked elsewhere.
Ransomware negotiation firm Coveware confirmed it has separately handled at least one incident involving contact from the same actor or group. Coveware's Senior Director of Incident Response, Elizabeth Cookson, said the third party reached out by email and claimed to have access to both a decryption key and the victim's stolen data.
Cookson noted that Coveware has seen similar "middlemen" operating under different names as far back as 2024, but distinguished this case from typical opportunistic scammers who only approach victims after an attack becomes public knowledge. "This type of interference on a non-public incident is much more concerning," she said.
Coveware explained that interference from an unauthorized third party with independent access to stolen data undermines the already shaky assurances ransomware victims rely on when paying an extortion demand. Even if a company pays the ransomware group directly, there is no guarantee that everyone with access to the stolen files, including a rogue affiliate, will honor any agreement not to leak or resell them. The firm suggested that growing distrust within RaaS ecosystems could encourage more affiliates to pursue side schemes like this one, seeking payouts outside their normal revenue-sharing arrangements with ransomware operators.
This is not the first time third parties have tried to profit by inserting themselves into ransomware incidents. BleepingComputer has previously warned about individuals creating forum accounts to privately approach victims who had already disclosed infections publicly, falsely claiming they could decrypt affected files for a fee. However, those scams targeted victims whose incidents were already public.
Ransom Busters' apparent foreknowledge of non-public attacks marks a more troubling escalation, since it suggests direct access to the ransomware operations themselves rather than opportunistic targeting of public disclosures.
Security researchers stress that any unsolicited offer of ransomware "recovery" services, particularly one referencing an incident that has not yet been made public, should be treated as a serious warning sign rather than a lifeline. Organizations that receive such contact are advised to:
- Avoid engaging directly or making any payment to the unknown party; instead, report the message immediately to an internal incident response team or a trusted third-party IR firm.
- Preserve the email and any related communications as evidence, since they may help investigators correlate the activity with known ransomware affiliates.
More broadly, security teams recommend that organizations rely on established incident response providers and law enforcement when navigating a ransomware attack rather than unsolicited offers of help, verify the identity and legitimacy of any party claiming to have obtained decryption keys or deleted stolen data, and treat promises of guaranteed data deletion with skepticism regardless of who is making them, since paying any criminal party offers no enforceable guarantee that stolen information will not be retained, resold, or used for future extortion.
The emergence of Ransom Busters illustrates a broader shift in the ransomware ecosystem, where even the criminal groups behind these attacks cannot fully trust their own affiliates. For victim organizations already under pressure during an active incident, that added layer of deception makes verifying the source of any recovery offer, however credible it appears, an essential step before taking any action.
Share:
Karolis Liucveikis
Experienced software engineer, passionate about behavioral analysis of malicious apps
Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion