Ransomware victims are facing a new kind of pressure campaign. Instead of receiving another demand from the attackers who stole their data, some companies are being contacted by a supposed recovery firm that says it can retrieve files and erase stolen copies.
The operation calls itself Ransom Busters. Its emails arrive before an incident is public and ask to speak with a chief executive or IT leader, an unusual approach that raises immediate questions about how the sender learned of a private breach.
Its researchers assess the alleged recovery service as a ransomware affiliate using a different route to extort victims.
GuidePoint Security said in a report shared with Cyber Security News (CSN) that the campaign was observed during responses to intrusions linked to DragonForce, Settra, and Anubis.
It adds another layer of uncertainty after a ransomware attack, when organizations must quickly protect operations, preserve evidence, and decide whom they can trust.
Rather than relying on a new malicious program, it relies on insider knowledge gained during ransomware intrusions, followed by email-based social engineering.
The goal is the same: turn stolen data and disrupted systems into a second payment opportunity.
Ransomware Hackers Pose as Recovery Firm
Ransom Busters LTD told victims it had infiltrated criminal servers, found their stolen data, and obtained access to encryption-key storage.
It promised to return files and delete every backup held by the ransomware operation, presenting itself as a rescuer rather than another extortionist.
The actor then demanded between $20,000 and $60,000 to remove the stolen information.
Researchers said it could demonstrate access to the same dataset held by the ransomware affiliate, a detail that strongly undercuts the image of an independent helper.
The claims also create a legal and practical problem. Unauthorized access to another group’s servers, even when those servers belong to criminals, may breach the Computer Fraud Abuse Act.
A legitimate recovery provider would not reasonably require payment to carry out such conduct.
The explanation for the fee was equally weak. Ransom Busters said free assistance would endanger its access to the criminals’ infrastructure, although a victim’s payment would not logically preserve that access.
The pattern points instead to a person trying to redirect ransom negotiations. That tactic fits a broader ecosystem in which affiliates use shared infrastructure but compete for profit.
Readers can see how these operations work in Cyber Security News’ DragonForce ransomware operating model, which describes the group’s cartel-style services, including panels and storage for partners.
GuidePoint’s incident-response team examined two cases in which Ransom Busters approached the victims.
The intrusions showed the same collection of tools for network discovery, cloud data theft, and remote control, despite attackers having many alternatives for each task.
Investigators found SoftPerfect Network Scanner used to map internal systems, s5cmd used to move data to AWS cloud storage, and the Remotely remote-management tool installed through a PowerShell script.
The same local backdoor password and the same attacker-controlled computer name appeared in both environments. No single shared tool proves who carried out an attack.
Yet the combined overlaps, along with activity spanning several ransomware-as-a-service programs, led the researchers to assess with moderate confidence that one affiliate was operating the Ransom Busters persona across cases.
DragonForce has appeared repeatedly in this activity. Its ability to support partners and apply pressure through stolen data is detailed in this DragonForce attack technique review, while a separate retail ransomware disruption report shows the real-world business impact of major attacks.
For victims, the immediate response should be to send any unsolicited recovery message to their incident-response team and preserve it as evidence.
They should involve law enforcement and trusted responders, verify every claim independently, and assume that payment offers no guarantee stolen data will be erased.
The central warning is simple: a criminal claiming to rescue a victim from another criminal is still asking for money without offering proof that the danger is over.
Ransomware recovery requires careful investigation, not a second bargain with an unknown actor.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Claimed recovery entity | Ransom Busters LTD | Name used in unsolicited emails sent to ransomware victims |
| Network discovery tool | SoftPerfect Network Scanner | Identified during forensic analysis of both linked intrusions |
| Data-exfiltration tool | s5cmd | Used to transfer victim data to AWS cloud storage |
| Remote-management tool | Remotely | Remote monitoring and management tool installed through a PowerShell script |
| Backdoor account password | Numlock!123 | Reused password for a local backdoor account in both investigated environments |
| Attacker-controlled hostname | DESKTOP-BBETH6K | Same hostname identified across both intrusions |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Click Here For The Original Source.
