discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Rogue ransomware affiliate poses as recovery firm to steal payments

A suspected ransomware affiliate, operating as "Ransom Busters," is contacting victims before attacks become public, falsely claiming to be a recovery firm that can provide decryption keys and delete stolen data for a fee.

By Lawrence Abrams·Aug 19·bleepingcomputer.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Rogue ransomware affiliate poses as recovery firm to steal payments
Image: bleepingcomputer.com

Security researchers have uncovered a deceptive scheme where a ransomware affiliate, dubbed Ransom Busters, impersonates a data recovery service. This group contacts victims of ransomware attacks prematurely, offering to resolve the incident by exploiting vulnerabilities in RaaS operations, but evidence suggests they are the original attackers attempting to double-extort victims.

Why it matters

This development introduces a new layer of deception and risk for ransomware victims, as it complicates recovery efforts and erodes trust within the already illicit ransomware-as-a-service ecosystem, potentially leading to more sophisticated double-extortion tactics.

Imagine a sneaky thief breaks into your house and steals your toys. Then, before you even tell anyone, a person knocks on your door pretending to be a special detective who knows all about your stolen toys and offers to get them back for a fee. But really, it's the same thief trying to trick you into paying them even more money!

Analysis

Ransom Busters

Ransom Busters is the moniker adopted by a suspected ransomware affiliate that has been observed contacting victims of cyberattacks. This group presents itself as a legitimate recovery service, offering to assist victims by providing decryption keys and deleting stolen data from ransomware servers. Their claims include exploiting vulnerabilities within the administrative panels of various ransomware-as-a-service (RaaS) operations, such as DragonForce, Settra, and Anubis.

The fees demanded by Ransom Busters for these purported services range from $20,000 to $60,000. The most suspicious aspect of their operation is their ability to contact victims before the ransomware attacks are publicly disclosed, raising immediate questions about how they acquire such sensitive, non-public information regarding the incidents.

GuidePoint Security

GuidePoint Security's Research and Intelligence Team (GRIT) was instrumental in disclosing this deceptive activity. GRIT responded to multiple ransomware attacks where victims received unsolicited emails from Ransom Busters, prompting their investigation. The timing of these emails, preceding any public announcement of the breaches, was a key indicator of suspicious behavior.

Through their analysis of two specific incidents, GRIT gathered compelling evidence suggesting that Ransom Busters is not a recovery firm but rather the ransomware affiliate responsible for the initial attacks. This evidence includes the consistent use of specific software like SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. Furthermore, the attackers consistently created a local backdoor account with the password 'Numlock!123' and utilized the same attacker-controlled hostname, 'DESKTOP-BBETH6K', across these incidents, strongly linking the recovery firm persona to the initial compromise.

Coveware

Ransomware negotiation firm Coveware corroborated GRIT's findings, confirming that they too have encountered at least one incident involving the same group or individual. Coveware's Senior Director of IR, Elizabeth Cookson, noted that this third party contacted victims via email, asserting access to both decryption keys and stolen data. This activity is distinct from typical "ambulance chasers" who usually contact victims only after an attack has been publicly disclosed.

Coveware has observed similar "middlemen" tactics under different names as far back as 2024, but emphasizes that Ransom Busters' interference in non-public incidents is far more concerning. The involvement of a rogue party with access to stolen data significantly increases risk for victims, as paying the original ransomware operation may no longer guarantee the secure deletion of data. Coveware posits that increased distrust within RaaS operations could fuel more such behavior, as affiliates seek to generate additional profits outside of their standard revenue-sharing agreements with ransomware operators.

Key points

  • A ransomware affiliate, 'Ransom Busters,' is posing as a recovery firm to double-extort victims.
  • Ransom Busters contacts victims before attacks are public, claiming access to decryption keys and stolen data via RaaS panel vulnerabilities.
  • GuidePoint Security's GRIT identified the scheme, linking Ransom Busters to the initial attacks through shared tools and tactics.
  • Coveware confirmed similar activity, noting this interference in non-public incidents is more concerning than typical 'ambulance chasers'.
  • This tactic increases risk for victims and could foster greater distrust within the ransomware-as-a-service ecosystem.
The Upside

The exposure of Ransom Busters by security firms like GuidePoint Security and Coveware could lead to increased awareness among potential victims, helping them avoid falling for this deceptive double-extortion tactic. This transparency might also prompt ransomware operators to better secure their own affiliate networks, reducing opportunities for such rogue behavior.

The Downside

This new tactic by rogue affiliates like Ransom Busters introduces significant complications for ransomware victims, as paying the original ransomware operator no longer guarantees data deletion if a third party also has access. The increased distrust within the RaaS ecosystem could lead to more affiliates attempting similar schemes, making recovery efforts more complex and costly for businesses.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityransomwarecybercrimedata-breachaffiliate-programcybersecurityextortion

Author

Lawrence Abrams

Intelligence analysis by

Gemini 2.5 Flash

Published

Aug 19, 2026

Source

bleepingcomputer.com

Share

Topics

securityransomwarecybercrimedata-breachaffiliate-programcybersecurityextortion

Related

More from this desk

Aug 20·bleepingcomputer.com

Microsoft says August Windows updates may cause gaming issues

Microsoft is investigating reports that its August 2026 Windows updates, specifically KB5121003, are causing some games to freeze, crash, or fail to launch on Windows 11 systems.

Aug 20·thehackernews.com

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

A critical flaw in the Elementor Pro WordPress plugin, CVE-2026-32475, allows unauthenticated attackers to upload dangerous PHP files and achieve remote code execution.

Aug 20·bleepingcomputer.com

OpenAI confirms ChatGPT is down as logins and signups fail

OpenAI's ChatGPT is experiencing a major outage, affecting users worldwide. Users are unable to sign in, create accounts, or load chats, including previous conversations.

Aug 19·bleepingcomputer.com

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud provider Sakura Internet disclosed a breach that may have impacted up to 1.36 million member accounts.