Ransom Busters: The Ransomware Affiliate Posing as a Recovery Service
A new and alarming trend has emerged in the ransomware landscape: a suspected ransomware affiliate is impersonating a recovery service named "Ransom Busters." This deceptive entity contacts victims of ransomware attacks *before* the incidents become public, offering decryption keys and data deletion services for a fee, raising serious questions about its true identity and motives.

Cybersecurity firm **GuidePoint Security's Research and Intelligence Team (GRIT)** has unveiled a disturbing development in the ransomware ecosystem. A group operating under the moniker **"Ransom Busters"** is actively contacting ransomware victims, claiming to be a legitimate recovery service capable of providing decryption keys and ensuring the deletion of stolen data.
### Unmasking the Deception
What makes **Ransom Busters** particularly concerning is their uncanny ability to reach victims before their attacks are publicly disclosed. This early notification immediately raised red flags for **GRIT**, suggesting an insider's knowledge of the attacks.
**Ransom Busters** purports to exploit vulnerabilities in the administrative panels of **Ransomware-as-a-Service (RaaS)** operations, such as **DragonForce**, **Settra**, and **Anubis**. They offer to delete stolen data from these servers for a fee ranging from **$20,000 to $60,000**.
### Evidence Points to Affiliation
However, **GRIT's** investigation, spanning multiple incidents, strongly indicates that **Ransom Busters** is not a genuine recovery firm. Instead, evidence suggests they are the very ransomware affiliate responsible for the initial attacks.
In two separate incidents, researchers observed consistent attacker methodologies, including the use of specific software like **SoftPerfect Network Scanner**, **s5cmd**, and the **Remotely** remote monitoring tool. Furthermore, the attackers consistently created a local backdoor account with the password **'Numlock!123'** and utilized the same attacker-controlled hostname, **'DESKTOP-BBETH6K'**.
This overlapping activity across different **RaaS** operations has led **GRIT** to conclude, with moderate confidence, that **Ransom Busters** is a single ransomware affiliate attempting to double-dip by extorting victims and potentially siphoning off payments from the **RaaS** gangs they collaborate with.
### The Risks for Victims
**GRIT** has not observed any victims paying **Ransom Busters** and strongly advises against it. In one instance, a victim chose to pay the underlying **RaaS** operation directly, and subsequently, their name and stolen data were not published on the ransomware's data leak site. Crucially, **GRIT** found no evidence that **Ransom Busters** leaked the stolen data outside the **RaaS** environment in this case.
Ransomware negotiation firm **Coveware** has also confirmed encountering this group, or individuals employing similar tactics. **Elizabeth Cookson**, Senior Director of IR at **Coveware**, noted, "This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data."
**Coveware** has observed similar "middlemen" since 2024, but distinguishes **Ransom Busters** from typical "ambulance chasers" who only engage after an attack is public. The pre-disclosure contact by **Ransom Busters** presents a far greater risk, as it increases distrust within **RaaS** operations and makes the payment process more precarious for victims. If a rogue party with access to stolen data is involved, paying the primary ransomware operator may no longer guarantee data security.
This emerging trend highlights the evolving sophistication of ransomware actors and the complex ethical and security dilemmas faced by victims.