Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Affiliate Exploits Trust with Fake Recovery Firm Tactics

Empty office with laptop on desk, daylight streaming through window.

"This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data," Elizabeth Cookson, Senior Director of IR at Coveware, told BleepingComputer.

Ransom Busters' pitch and pricing

GuidePoint Security's Research and Intelligence Team (GRIT) says a group calling itself "Ransom Busters" has been contacting victims of ransomware before those incidents were publicly disclosed, offering to provide decryption keys and to delete stolen data for a fee. The group claimed to exploit vulnerabilities in administrative panels used by ransomware-as-a-service (RaaS) operations and offered to delete data from ransomware servers belonging to named operations including DragonForce, Settra, and Anubis. Reported asking prices ranged from $20,000 to $60,000.

Technical overlap tying Ransom Busters to the intrusions

GRIT examined two incidents and found the same software and tactics in both attacks, findings that led investigators to question whether Ransom Busters was a legitimate recovery firm. The incidents used SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. In both cases attackers created a local backdoor account using the password 'Numlock!123' and used the same attacker-controlled hostname, 'DESKTOP-BBETH6K.' GRIT observed overlapping activity across multiple RaaS operations and says, with moderate confidence, that Ransom Busters is a single ransomware affiliate using its access to steal ransom payments from the ransomware gangs it works with.

GRIT and Coveware responses

GRIT disclosed the activity after responding to several recent ransomware attacks in which victims received emails from Ransom Busters. The researchers report no evidence that victims paid Ransom Busters and discourage victims from doing so. In one incident GRIT described, the victim instead paid the RaaS operation behind the attack; GRIT found that the victim's name and the stolen data were not published on the ransomware operation's data leak site, and they found no evidence that Ransom Busters leaked the stolen data outside the RaaS environment.

Negotiation firm Coveware confirmed to BleepingComputer that its team recently responded to at least one incident in which the same group or individual contacted a victim. Elizabeth Cookson's description of that contact — claiming simultaneous access to both the decryption key and the stolen data — aligns with GRIT's report and with prior warnings about third-party actors approaching victims. Coveware told BleepingComputer that similar "middlemen" have appeared under other names since 2024, but that the current pattern is unusual because the third party reaches out on non-public incidents.

How incident responders, negotiators, and RaaS operators are affected

  • Incident responders and security teams: GRIT's findings underline a new vector of interference — emails to victims before public disclosure — that responders should treat as potentially coming from an actor with hands-on access to the victim environment. GRIT explicitly discourages victims from paying these third parties.
  • Negotiation firms and negotiators: Coveware warns that interference from a rogue party with access to stolen data increases risk for victims because paying the primary ransomware operator may not ensure everyone with access will honor a payment agreement.
  • Ransomware-as-a-Service operators and affiliates: Coveware says increased distrust within RaaS operations could incentivize affiliates to seek additional profits outside established revenue-sharing arrangements — a dynamic GRIT's moderate-confidence assessment suggests is already occurring.

Conclusion: a trust problem inside the criminal ecosystem

Two investigative threads run through the record published to date: technical overlap tying the same tools, password, and hostname to multiple incidents, and corroborating accounts from both GRIT and Coveware that a third party approached victims before public disclosure. Together they support GRIT's assessment — with moderate confidence — that Ransom Busters may be a rogue affiliate taking payments meant for ransomware operators. GRIT and Coveware both flag the practical consequence for victims: paying an intermediary or the primary operator does not guarantee control over stolen data if multiple parties have independent access.

That observation closes the immediate loop on the reported incidents but opens a broader operational question already voiced by negotiators: if increased distrust inside RaaS ecosystems leads to more affiliates trying to monetize access directly, will victims face more fractured extortion chains and less ability to resolve incidents through single-point negotiation? For now, GRIT advises victims not to pay Ransom Busters, and investigators are left to follow the overlapping technical signals and the money trails that those signals imply.

Original BleepingComputer story