‘Ransom Busters’: Ransomware Actor Poses as Incident-Recovery Service

Ransomware Actors Masquerade as Incident-Recovery Services, Targeting Victims with Fake Offers of Aid

A new and disturbing trend has emerged in the world of ransomware, where attackers are posing as incident-recovery services to deceive victims into paying them again. The tactic, uncovered by researchers at GuidePoint Security, involves a malicious entity claiming to have infiltrated the servers of multiple criminal groups and offering to return stolen files to victims for a hefty fee.

The “Ransom Busters” entity, as it calls itself, sends emails to ransomware victims, boasting that they have gained access to encryption keys and can help unlock encrypted data. In some cases, Ransom Busters even claims to have deleted the stolen data from the ransomware groups’ servers, all for a fee of between $20,000 to $60,000.

But there’s a catch: this is not an offer of genuine assistance. According to Justin Timothy, principal threat intelligence consultant at GuidePoint Security, Ransom Busters’ tactics are designed to divert ransom payments away from the original ransomware operation and into the pockets of the attackers themselves. By claiming to have access to encryption keys and deleted data, Ransom Busters is attempting to create a false sense of urgency and convince victims that they need to pay up quickly.

But how does this work? In most ransomware operations, affiliates do not have unilateral control over every copy of stolen data or the broader extortion infrastructure. This means that victims cannot verify claims that data has been deleted or that all parties with access to the information have relinquished it. Ransom Busters is likely using its affiliate access to manipulate this situation and reap the financial benefits.

One red flag is that Ransom Busters reached out to victims before the ransomware attack became public knowledge, a move that undermines the typical incident-response model where firms offer their services after an attack is disclosed. Additionally, Ransom Busters’ claims of accessing administrative panels of ransomware-as-a-service (RaaS) actors could potentially be considered a violation of the US government’s Computer Fraud Abuse Act.

The GuidePoint Digital Forensics and Incident Response team responded to two incidents involving Ransom Busters, finding that the intrusions were notably similar in terms of tooling used and persistence mechanisms within victim networks. Overlaps in tools for internal reconnaissance, data exfiltration, and remote monitoring and management (RMM) suggested a coordinated effort.

Ultimately, researchers at GuidePoint believe with moderate confidence that Ransom Busters is not a true third-party researcher but rather a single ransomware affiliate working with multiple RaaS actors to implement the same tactics across victim environments. By posing as an incident-recovery service, Ransom Busters is attempting to monetize victims outside of the traditional RaaS payment structure.

So what can you do to protect yourself from these types of attacks? The best advice is to remain vigilant and cautious when approached by entities claiming to offer assistance after a ransomware attack. Verify the authenticity of any claims made and do not rush into paying fees without thoroughly investigating the situation. By staying informed and taking proactive steps, you can minimize your risk of falling victim to these types of scams.


Source: Dark Reading — 2026-08-18