A suspected ransomware affiliate is posing as a ransomware recovery company called Ransom Busters. The group claims it can contact victims before a ransomware attack becomes public, provide decryption keys, and delete stolen data for a fee.
The GuidePoint Security Research and Intelligence Team (GRIT) reported the activity after investigating several recent ransomware incidents. In each case, victims received emails from Ransom Busters offering assistance with data recovery and ransomware negotiations.
The messages raised concerns because they were sent before the attacks had been publicly disclosed. This suggests that Ransom Busters may have had direct knowledge of the incidents, potentially because the group was involved in carrying them out.
Ransom Busters claimed that it exploited a vulnerability in the administration panel used by ransomware-as-a-service (RaaS) operations. According to the group, this gave it access to victims’ decryption keys and stolen data.
The group offered to remove stolen information from ransomware servers operated by DragonForce, Settra, and Anubis. The alleged data deletion service reportedly cost between $20,000 and $60,000.
However, evidence from the investigated incidents led GRIT to conclude that Ransom Busters is likely the ransomware affiliate responsible for the attacks, rather than an independent recovery company.
In both incidents, the attackers used the same tools, including SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring platform. Investigators also identified matching tactics, such as creating a local backdoor account with the password “Numlock!123” and using the attacker-controlled hostname “DESKTOP-BBETH6K.”
GRIT has observed overlapping activity across multiple ransomware-as-a-service operations. The research team believes with moderate confidence that Ransom Busters is a single ransomware affiliate using access to victims and ransomware infrastructure to extort additional payments from both victims and cooperating ransomware gangs.
GRIT told BleepingComputer that it has not seen evidence of victims paying Ransom Busters and advises organizations not to do so. In one related incident, however, the victim paid the RaaS operation responsible for the ransomware attack instead.
Researchers said the victims’ names and stolen data did not appear on the ransomware groups’ data-leak websites. They also found no evidence that Ransom Busters leaked the stolen information outside the relevant ransomware-as-a-service environments.
Ransomware negotiation firm Coveware confirmed to BleepingComputer that it recently handled at least one incident in which the same group or individual contacted the victim.
“This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data,” Elizabeth Cookson, senior director of investor relations at Coveware, told BleepingComputer.
Coveware said it has encountered similar ransomware “middlemen” operating under different names since 2024. However, the company said this activity differs from typical “ambulance chasers,” which usually contact victims only after a ransomware attack becomes public.
“This kind of interference in a private case is far more alarming,” Lizzy told BleepingComputer.
Coveware warned that unauthorized third parties gaining access to stolen data can increase risks for ransomware victims. Paying the ransomware group may not ensure that every person with access to the data will honor an agreement not to publish or sell it.
The company said that growing distrust within ransomware-as-a-service operations could drive more affiliates to pursue additional profits outside standard revenue-sharing agreements with ransomware operators.
BleepingComputer previously warned that fake or questionable ransomware recovery services create forum accounts and privately contact victims who publicly disclose ransomware infections. These services often claim they can decrypt affected files or recover stolen data.
However, while those services typically approach victims after an attack has been publicly reported, Ransom Busters’ apparent knowledge of private ransomware incidents is considerably more concerning.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




