A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure.
GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments from established ransomware-as-a-service operations.
However, unsolicited outreach based on non-public breach details is a major warning sign. In the observed emails, sent under the “Ransom Busters LTD” name, the actor seeks contact with CEOs or IT leaders and asserts that it has infiltrated criminal ransomware servers.
The emails claim the operator discovered a victim’s exfiltrated data on compromised ransomware infrastructure, accessed decryption-key storage, and can return files while destroying backups held by the original attackers.
Ransom Busters further alleges access to the administrative panels of multiple ransomware-as-a-service, or RaaS, operations claims that have not been independently verified.
GRIT observed the activity while responding to intrusions associated with DragonForce, Settra, and Anubis.
During engagement with the actor, researchers confirmed that Ransom Busters possessed the same stolen datasets held by the ransomware affiliate responsible for each intrusion.
The entity then offered to delete the data for payments ranging from $20,000 to $60,000.
The proposal represents an alternate form of extortion rather than a credible recovery path.
Paying an unknown criminal intermediary provides no assurance that copies of stolen data will be removed, that encryption keys are genuine, or that the attacker no longer retains network access.
GuidePoint Researchers said that, the campaign is notable because Ransom Busters contacts victim organizations before their attacks become public. Legitimate incident-response and cybersecurity firms may approach publicly disclosed victims.
Ransomware operators frequently keep duplicate exfiltrated data for resale, later leaks, or repeat extortion attempts.
Ransom Busters Ransomware
Ransom Busters claimed that charging victims was necessary to preserve its access to ransomware infrastructure.
GRIT found that explanation implausible: whether a victim pays would not logically determine the actor’s ability to retain unauthorized access to a criminal portal.
Moreover, conducting unauthorized access or deletion activity against another party’s systems could itself create legal exposure under the U.S. Computer Fraud and Abuse Act.
GuidePoint’s DFIR team investigated two affected environments and identified highly similar intrusion artifacts.
Both cases involved SoftPerfect Network Scanner for internal reconnaissance, s5cmd for AWS-based cloud exfiltration, and the Remotely remote-monitoring-and-management tool deployed using a PowerShell script.
The investigators also found a local backdoor account configured with the identical password Numlock!123 and an attacker-controlled hostname, DESKTOP-BBETH6K, in both intrusions.
Although affiliates can reuse shared playbooks, the repeated combination of tooling, credentials, and host artifacts across incidents linked to separate RaaS brands strengthens the case for a single operator.
GRIT therefore assesses that Ransom Busters is likely an affiliate operating across multiple ransomware ecosystems, repackaging direct criminal access as a paid “rescue” service.
The tactic potentially lets an affiliate monetize a victim independently while undermining the original ransomware operation’s negotiation process.
Organizations receiving unsolicited recovery offers during a ransomware incident should preserve the messages, avoid negotiating independently, and immediately provide the communications to their incident-response provider and law enforcement.
Teams should treat any claims of data deletion or decryption-key access as unverified until independently validated.
The case illustrates how ransomware monetization is evolving beyond encryption and leak-site threats.
Victims now face potential secondary extortion from actors posing as helpers making disciplined incident response, evidence preservation, and trusted DFIR engagement essential.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model. -> Register Now
