Cybersecurity

Ransomware-Linked Entity Poses as Recovery Company to Steal Payments

Research teams have warned of an entity known as Ransom Busters that contacts ransomware attack victims before the attacks are announced and demands up to $60,000 in exchange for decryption keys and deletion of stolen data. Evidence suggests that the entity may be a partner affiliated with the ransomware operations themselves, rather than an independent recovery company.

2026-08-19
3 min read
8 views
فريق تحرير certi.news
Ransomware-Linked Entity Poses as Recovery Company to Steal Payments

GuidePoint Security has warned of activity by an entity called Ransom Busters, which poses as a service for recovering ransomware attack victims, while evidence suggests it may be the party carrying out the attacks or an affiliated partner. The entity contacts victims before the attacks become public and offers to provide decryption keys and delete stolen data in exchange for money.

The GuidePoint Security research and intelligence team, known as GRIT, uncovered the activity after responding to several recent ransomware attacks whose victims received messages from Ransom Busters. The entity’s knowledge of the attacks before their disclosure immediately raised suspicions, as it was unclear how a purported recovery service had gained access to information about undisclosed incidents.

Claiming Access to Encryption Keys and Data

Ransom Busters claimed that it had exploited vulnerabilities in administrative panels used by ransomware-as-a-service operations, or RaaS, allowing it to access encryption keys and data stolen from victims. The entity demanded between $20,000 and $60,000 to delete the data from the ransomware operations’ servers, including servers linked to the DragonForce, Settra, and Anubis groups.

However, GRIT linked two incidents in which identical technical and operational indicators appeared. In both cases, the attackers used the same tools, including SoftPerfect Network Scanner, s5cmd, and the Remotely remote-monitoring tool. They also created a backdoor local account using the password Numlock!123 and used the same hostname controlled by the attackers: DESKTOP-BBETH6K.

Why Does This Development Matter?

GRIT says, with moderate confidence, that the overlapping activity across multiple RaaS operations suggests the presence of a single partner exploiting its access to gang attacks to steal additional payments outside the usual revenue-sharing arrangements. The company has not yet seen a victim pay Ransom Busters and urged victims not to pay it. In one case, the victim instead paid the ransomware operation behind the attack.

Coveware, a company specializing in ransomware attack negotiations, confirmed to BleepingComputer that it had recently handled at least one incident in which the same entity, or an individual associated with it, contacted a victim claiming to possess the decryption key and stolen data. Coveware noted that it has observed similar brokers operating under other names since 2024, but the difference here is that Ransom Busters contacted victims regarding incidents that had not yet been disclosed.

This intervention increases risks for victims because paying the primary operator may not guarantee that every party possessing a copy of the data will refrain from leaking it. So far, GRIT has found no evidence that the data was published outside the RaaS operations’ environment, and the data of one victim was not published on the ransomware operation’s leak site. Coveware believes that declining trust between ransomware operators and their partners may drive more affiliates to seek independent profits.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news