Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Affiliate Exploits Trust with Fake Recovery Service

Person sits at desk, scrutinizing laptop screen with skepticism in a dimly lit home office.

"This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data," Elizabeth Cookson, Senior Director of IR at Coveware, told BleepingComputer.

Ransom Busters' pitch: paying for keys and data deletion

GuidePoint Security's Research and Intelligence Team (GRIT) disclosed that a suspected ransomware affiliate is posing as a recovery service calling itself "Ransom Busters." According to GRIT, the group has contacted victims before incidents were publicly disclosed, offering decryption keys and the deletion of stolen data in exchange for payments between $20,000 and $60,000.

The messages claimed Ransom Busters had exploited vulnerabilities in administrative panels used by ransomware-as-a-service (RaaS) operations, giving it access to encryption keys and stolen files. GRIT said the group offered to delete stolen data from servers belonging to RaaS families identified in their reporting, including DragonForce, Settra, and Anubis.

Technical fingerprints tying the contacts to the attacks

GRIT examined multiple incidents and identified overlapping technical artifacts across at least two cases. The same software suite appeared in both incidents: SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. Attackers also created a local backdoor account using the password "Numlock!123" and used a consistent attacker-controlled hostname, "DESKTOP-BBETH6K."

Those shared tools and tactics are the evidence GRIT cites to argue the email contacts were not independent third-party helpers but instead likely the affiliate responsible for the compromises.

GRIT's assessment and confidence

From the forensic overlap, GRIT concluded—"with moderate confidence"—that Ransom Busters is a single ransomware affiliate leveraging its access to siphon ransom payments from the RaaS operations it works with. In two incidents specifically examined, GRIT says the evidence points toward the contacting party actually being the on-the-ground affiliate rather than an outside recovery firm.

GRIT told BleepingComputer it has not observed any victims paying Ransom Busters and explicitly discourages victims from paying the group. In one referenced incident, however, the victim paid the RaaS operation itself. GRIT also reported they found no evidence the affiliate leaked stolen data outside the RaaS environments and that the victim name and stolen data were not published on the ransomware operation's data leak site in that case.

Coveware confirmation and the new danger of non-public interference

Ransomware negotiation firm Coveware confirmed to BleepingComputer that they recently responded to at least one incident where the same actor contacted a victim claiming to hold decryption keys and stolen data. Elizabeth Cookson framed the activity as distinct from previously observed "ambulance chasers" who approach victims only after incidents are public.

Coveware warned that interference during non-public incidents is "much more concerning." Their analysts told BleepingComputer that a rogue intermediary with access to stolen data raises the risk that paying the primary ransomware operation will not prevent others with access from publishing or monetizing the data—because additional parties may not honor any negotiated agreement.

Coveware also told BleepingComputer its own experience reaches back to 2024 with similar middlemen using other names; but the defining difference with Ransom Busters, they said, is prior knowledge of incidents that had not been publicly disclosed.

What this means for security teams, Coveware, and affected enterprises

  • Security teams and incident responders: overlaps in tooling (SoftPerfect Network Scanner, s5cmd, Remotely), consistent backdoor credentials ("Numlock!123") and a repeated hostname ("DESKTOP-BBETH6K") are signals to flag when triaging active breaches. GRIT's findings point to the value of correlating forensic artifacts across incidents before treating unsolicited offers as legitimate.
  • Coveware and negotiation firms: confirmed contact by the same actor suggests negotiators should treat unsolicited third-party claims about keys or data as potentially opportunistic and advise clients accordingly; Coveware explicitly described the behavior as more concerning than post-public "ambulance chaser" approaches.
  • Affected enterprises and procurement leaders: the appearance of a third party claiming to possess keys or to delete stolen files complicates the calculus of whether to engage a RaaS operator directly. GRIT discouraged payments to Ransom Busters, and Coveware warned that paying the primary actor may not bind all parties with access.

GRIT's reporting draws a narrow but clear line: the actors contacting victims before disclosures may in some cases be the attackers themselves seeking side profits. Coveware's confirmation and the technical overlaps GRIT documents make that claim plausible in the incidents they examined, and both sources emphasize caution—not only about paying anyone who claims to help, but about assuming a single payment resolves who controls or might later disseminate stolen data.

The record the teams have laid out leaves a pointed question in plain sight: when access to stolen data is fragmented inside RaaS ecosystems, how will victims and their advisers verify who truly controls decryption keys or the future fate of exposed files? For now, GRIT discourages payments to Ransom Busters and Coveware characterizes non-public interference as an escalation of risk.

Read the original BleepingComputer report