Ransomware Affiliate Poses as Incident-Recovery Service, Luring Victims with False Promises of Data Recovery
A sophisticated and brazen tactic has been uncovered by cybersecurity researchers, where a ransomware affiliate is posing as an incident-recovery service to lure victims into paying them for help in recovering their stolen data. Dubbed “Ransom Busters,” this malicious entity claims to have infiltrated the servers of multiple criminal groups and gained access to encryption keys that can be used to unlock victims’ files.
According to a recent report from GuidePoint Research and Intelligence Team (GRIT), Ransom Busters has been sending emails to cyberattack victims, offering to return their files and destroy all backups held by the ransomware group for a hefty fee of between $20,000 to $60,000. The email claims that Ransom Busters has also gained access to encryption keys that can be used to help victims access their files.
However, experts warn that this is not an offer of genuine assistance, but rather a ploy by the ransomware affiliate to divert ransom payment discussions away from the original ransomware operation. GRIT believes that Ransom Busters’ ultimate goal is to monetize victims outside the traditional ransomware-as-a-service (RaaS) payment structure.
There are several red flags behind Ransom Busters’ claims, including the fact that they reach out to victims before the ransomware attack becomes public knowledge. Incident-response firms typically offer their services after an attack has been disclosed, not before. Furthermore, Ransom Busters’ claim of accessing the administrative panel of RaaS actors raises concerns about potential Computer Fraud Abuse Act (CFAA) violations.
In two separate incidents where GRIT’s Digital Forensics and Incident Response (DFIR) team responded to Ransom Busters’ contacts with victims, they found notable similarities in the intrusions. The tools used for internal reconnaissance, data exfiltration, and remote monitoring and management (RMM) were identical, and local backdoor accounts shared a password. This suggests that Ransom Busters is not a true third-party researcher, but rather a single ransomware affiliate implementing the same tactics across victim environments.
The tactics employed by Ransom Busters are actually undermining the core RaaS business model, where affiliates typically do not have unilateral control over every copy of stolen data or the broader extortion infrastructure. This means that victims have little ability to verify claims that data has actually been deleted or that all parties with access to the information have relinquished it.
As we’ve seen in numerous RaaS operations, the primary goal is to extort payment from victims while maintaining control over the stolen data and its subsequent sale on dark web markets. Ransom Busters’ attempt to monetize victims outside this structure may be an effort to siphon revenue away from the original ransomware operation.
In light of these findings, it’s essential for organizations to remain vigilant against such tactics. When receiving emails or offers of assistance after a ransomware attack, it’s crucial to verify the authenticity of the claims and not fall prey to false promises. Always be cautious when dealing with unsolicited communications from unknown entities, especially those claiming to offer help in recovering stolen data.
Source: Dark Reading — 2026-08-18