Ransom Busters, a suspected rogue ransomware affiliate, has been posing as a recovery service to steal payments from victims. This group claims it can provide decryption keys and delete stolen data for a fee, but evidence suggests they are actually the ones responsible for the attacks.
The activity was uncovered by GuidePoint Security’s Research and Intelligence Team (GRIT) after responding to several recent ransomware attacks in which victims received emails from Ransom Busters offering to help recover from the attack. What’s alarming is that these messages were sent before the attacks became public, raising questions about how they knew about the cyberattacks in the first place.
Ransom Busters claims it exploited vulnerabilities in administrative panels used by ransomware-as-a-service (RaaS) operations, giving it access to encryption keys and data stolen from victims. The group offered to delete the stolen data from ransomware servers, including those belonging to DragonForce, Settra, and Anubis, for between $20,000 and $60,000. However, GRIT believes Ransom Busters is likely not a true recovery firm, but rather the ransomware affiliate responsible for the attacks.
In two separate incidents, GRIT observed that the attackers used the same software, including SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. They also utilized the same tactics, such as creating a local backdoor account using the password ‘Numlock!123’ and the same attacker-controlled hostname, ‘DESKTOP-BBETH6K’. GRIT says it observed overlapping activity across multiple RaaS operations and believes with moderate confidence that Ransom Busters is a single ransomware affiliate using its access to steal ransom payments from the ransomware gangs it works with.
The researchers warn that paying Ransom Busters may not guarantee the safe return of stolen data. In one incident, a victim paid Ransom Busters instead of the RaaS operation behind the attack, but the stolen data was not published on the ransomware operation’s data leak site. However, GRIT found no evidence that Ransom Busters leaked the stolen data outside the RaaS environment.
Coveware, a ransomware negotiation firm, has also encountered similar “middlemen” using other names as far back as 2024. They believe this activity is distinct from the typical “ambulance chasers” who contact victims only after their attacks have been publicly disclosed. Coveware says interference from a rogue party with access to stolen data increases risk for victims, and paying the ransomware operation may no longer ensure that everyone with access to the data will honor an agreement not to leak it.
The emergence of Ransom Busters highlights the increasing complexity of ransomware attacks. With more affiliates attempting to generate additional profits outside of normal revenue-sharing arrangements with ransomware operators, this behavior is likely to become more prevalent. As a result, victims should be cautious when approached by third-party recovery services, especially those that claim they can decrypt affected files.
In light of this development, it’s essential for organizations and individuals to remain vigilant when dealing with ransomware attacks. If you’re contacted by Ransom Busters or any other suspicious group claiming to offer recovery services, do not pay them. Instead, report the incident to law enforcement and seek guidance from trusted security professionals. Only by working together can we mitigate the impact of these sophisticated cyberattacks.
Source: Bleeping Computer — 2026-08-19