A suspected ransomware affiliate is posing as an independent recovery company under the name Ransom Busters.
GuidePoint Security’s Research and Intelligence Team, known as GRIT, uncovered the activity while responding to several ransomware incidents. In each case, the victims received emails from Ransom Busters offering assistance. The messages immediately raised suspicions because they arrived before the attacks had become public, prompting questions about how the senders knew about the incidents in the first place.
Ransom Busters claimed it had exploited vulnerabilities in the management panels of several ransomware-as-a-service operators, giving it access to decryption keys and stolen victim data. For payments ranging from $20,000 to $60,000, the group offered to delete stolen data from the servers of various ransomware groups, including DragonForce, Settra, and Anubis.
Same Tools and Traces as the Original Attacks
Evidence from two specific incidents led GRIT to conclude, with moderate confidence, that Ransom Busters is not a legitimate recovery company. Instead, researchers believe it may be the same ransomware affiliate responsible for the original attacks.
In both cases, the attackers used the same software, including SoftPerfect Network Scanner, the s5cmd tool, and the remote management software Remotely. They also followed the same operational pattern, creating a local backdoor account with the password Numlock!123 and using the same attacker-controlled hostname, DESKTOP-BBETH6K.
GRIT also observed overlapping activity across several different ransomware-as-a-service operations.
According to GRIT, it has not yet seen a case in which a victim actually paid Ransom Busters, and the researchers explicitly advise against doing so. In one documented incident, the affected company instead paid the ransomware group behind the attack. The victim’s name and stolen data were subsequently not published on the group’s leak site. Researchers also found no evidence that Ransom Busters itself had published the data outside the ransomware group’s infrastructure.
Coveware Confirms a Similar Case
Ransomware negotiation firm Coveware also confirmed that it recently handled at least one comparable case in which the same group or individual contacted a victim.
Elizabeth Cookson, Senior Director of Incident Response at Coveware, said the third party contacted the victim by email and claimed to possess both the decryption key and the stolen data. Coveware has been aware of similar intermediaries operating under different names since 2024. However, the company stressed that this behavior differs significantly from conventional opportunists who only emerge after an incident has become public.
Interference in an attack that has not yet been publicly disclosed is considerably more concerning. In such a scenario, paying the original ransomware group may no longer guarantee that everyone with access to the stolen data will honor an agreement not to publish it.
Coveware believes that growing distrust within individual ransomware-as-a-service operations could lead to more cases of this kind. Individual affiliates may increasingly try to generate additional profits beyond their regular revenue shares from ransomware operators.
(Editorial Team)