Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Affiliate Exploits Fellow Extortionists with 'Recovery' Scam

Dimly lit, cluttered office with scattered equipment and a lone chair in front of a computer screen.

"moderate confidence," GuidePoint's Research and Intelligence Team wrote — an understated phrase for an accusation that turns a familiar criminal model on its head: a ransomware affiliate pretending to be a recovery service and undercutting the very gangs it works with.

Ransom Busters' pitch to victims

GuidePoint Security discovered an operation styling itself "Ransom Busters" contacting victims before their incidents were publicly disclosed. The outfit offered to delete stolen data and restore encrypted files for a one-time payment far below the original extortion demand — typically between $20,000 and $60,000, GuidePoint reported. Ransom Busters told victims it had allegedly penetrated the ransomware gangs' own infrastructure and recovered the stolen datasets and encryption keys, presenting those claims alongside demonstrations of access to the same datasets the primary attackers held.

Forensic fingerprints: tools, accounts, and a hostname

GuidePoint's GRIT team examined two incidents in which Ransom Busters approached victims and identified an unusual, consistent toolbox and set of artifacts. Both intrusions showed reconnaissance performed with SoftPerfect Network Scanner, use of s5cmd to transfer data into AWS cloud storage, and deployment of the Remotely remote-management tool installed via PowerShell. In both environments the attacker created a local backdoor account using the password "Numlock!123." The same attacker-controlled hostname, "DESKTOP-BBETH6K," also appeared in both intrusions. Those repeated specifics are the foundation for GuidePoint's assessment that a single actor or affiliate is involved rather than unrelated operators converging on the same victims by chance.

Links to DragonForce, Settra, and Anubis

GuidePoint unearthed Ransom Busters while investigating attacks associated with the ransomware groups DragonForce, Settra, and Anubis. The security firm said it has seen the same activity across multiple ransomware-as-a-service (RaaS) programs, and thereby assessed with "moderate confidence" that an affiliate is moonlighting across several gangs. The apparent business model, as GuidePoint lays it out, is simple and brazen: the affiliate leverages access obtained during intrusions to offer victims a cheaper payoff, diverting funds that otherwise would go to the affiliate's ransomware employers.

Why payment offers should raise alarms

GuidePoint explicitly warned that paying purported rescuers provides no assurance the stolen information will be deleted. The firm's note — blunt and practical — amounts to a twofold warning: the offer itself is suspicious because it arrives before public disclosure of the incident, and the alleged remedy is not verifiable. As GuidePoint put it in plain terms: if a mysterious stranger offers to "make the whole problem disappear for $20,000," recipients should question how the caller knew about the breach in the first place.

What this means for technologists, affected enterprises, and ransomware affiliates

  • Technologists and security teams: Watch for the specific indicators GuidePoint found — SoftPerfect Network Scanner, s5cmd uploads to AWS, Remotely deployed by PowerShell, the "Numlock!123" account, and the "DESKTOP-BBETH6K" hostname — as potential signs not only of a ransomware attack but of an internal affiliate attempting to divert payments. Those artifacts are concrete starting points for detection and containment efforts.
  • Affected enterprises and procurement leaders: Treat unsolicited recovery offers with extreme skepticism, especially offers that appear before a matter becomes public. The advertised price range, $20,000–$60,000, may look attractive compared with typical extortion demands, but GuidePoint warns there is no guarantee the data will be removed after payment.
  • Ransomware affiliates and operators: The pattern described by GuidePoint suggests affiliates can and do operate across multiple RaaS programs, but the duplication of tools and credentials also creates a forensic trail. That same trail enables defenders and investigators to link incidents and identify irregular behavior within criminal networks.

The GuidePoint account leaves a sharp, focused takeaway: when the "rescuer" looks too helpful, it may be part of the same problem. The technical fingerprints — tools, account names, and hostnames — tie a persuasive narrative to concrete evidence and supply investigators with actionable leads. And the most practical question the incidents pose is the one GuidePoint already posed for victims: how did this purported savior get your number before you told anyone?

Source: The Register — Ransomware crook poses as recovery firm to steal payments from fellow extortionists