Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate, operating as "Ransom Busters," is contacting victims before attacks become public, falsely claiming to be a recovery firm that can provide decryption keys and delete stolen data for a fee.
Intelligence analysis by Gemini 2.5 Flash

Security researchers have uncovered a deceptive scheme where a ransomware affiliate, dubbed Ransom Busters, impersonates a data recovery service. This group contacts victims of ransomware attacks prematurely, offering to resolve the incident by exploiting vulnerabilities in RaaS operations, but evidence suggests they are the original attackers attempting to double-extort victims.
Imagine a sneaky thief breaks into your house and steals your toys. Then, before you even tell anyone, a person knocks on your door pretending to be a special detective who knows all about your stolen toys and offers to get them back for a fee. But really, it's the same thief trying to trick you into paying them even more money!
Analysis
Ransom Busters
Ransom Busters is the moniker adopted by a suspected ransomware affiliate that has been observed contacting victims of cyberattacks. This group presents itself as a legitimate recovery service, offering to assist victims by providing decryption keys and deleting stolen data from ransomware servers. Their claims include exploiting vulnerabilities within the administrative panels of various ransomware-as-a-service (RaaS) operations, such as DragonForce, Settra, and Anubis.
The fees demanded by Ransom Busters for these purported services range from $20,000 to $60,000. The most suspicious aspect of their operation is their ability to contact victims before the ransomware attacks are publicly disclosed, raising immediate questions about how they acquire such sensitive, non-public information regarding the incidents.
GuidePoint Security
GuidePoint Security's Research and Intelligence Team (GRIT) was instrumental in disclosing this deceptive activity. GRIT responded to multiple ransomware attacks where victims received unsolicited emails from Ransom Busters, prompting their investigation. The timing of these emails, preceding any public announcement of the breaches, was a key indicator of suspicious behavior.
Through their analysis of two specific incidents, GRIT gathered compelling evidence suggesting that Ransom Busters is not a recovery firm but rather the ransomware affiliate responsible for the initial attacks. This evidence includes the consistent use of specific software like SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. Furthermore, the attackers consistently created a local backdoor account with the password 'Numlock!123' and utilized the same attacker-controlled hostname, 'DESKTOP-BBETH6K', across these incidents, strongly linking the recovery firm persona to the initial compromise.
Coveware
Ransomware negotiation firm Coveware corroborated GRIT's findings, confirming that they too have encountered at least one incident involving the same group or individual. Coveware's Senior Director of IR, Elizabeth Cookson, noted that this third party contacted victims via email, asserting access to both decryption keys and stolen data. This activity is distinct from typical "ambulance chasers" who usually contact victims only after an attack has been publicly disclosed.
Coveware has observed similar "middlemen" tactics under different names as far back as 2024, but emphasizes that Ransom Busters' interference in non-public incidents is far more concerning. The involvement of a rogue party with access to stolen data significantly increases risk for victims, as paying the original ransomware operation may no longer guarantee the secure deletion of data. Coveware posits that increased distrust within RaaS operations could fuel more such behavior, as affiliates seek to generate additional profits outside of their standard revenue-sharing agreements with ransomware operators.
Key points
- A ransomware affiliate, 'Ransom Busters,' is posing as a recovery firm to double-extort victims.
- Ransom Busters contacts victims before attacks are public, claiming access to decryption keys and stolen data via RaaS panel vulnerabilities.
- GuidePoint Security's GRIT identified the scheme, linking Ransom Busters to the initial attacks through shared tools and tactics.
- Coveware confirmed similar activity, noting this interference in non-public incidents is more concerning than typical 'ambulance chasers'.
- This tactic increases risk for victims and could foster greater distrust within the ransomware-as-a-service ecosystem.
The exposure of Ransom Busters by security firms like GuidePoint Security and Coveware could lead to increased awareness among potential victims, helping them avoid falling for this deceptive double-extortion tactic. This transparency might also prompt ransomware operators to better secure their own affiliate networks, reducing opportunities for such rogue behavior.
This new tactic by rogue affiliates like Ransom Busters introduces significant complications for ransomware victims, as paying the original ransomware operator no longer guarantees data deletion if a third party also has access. The increased distrust within the RaaS ecosystem could lead to more affiliates attempting similar schemes, making recovery efforts more complex and costly for businesses.



