Ransom Busters: Attackers Pose as Recovery Experts to Double-Dip on Victims
A malicious actor is exploiting ransomware victims by pretending to be a white-hat recovery service to extort additional payments.
A malicious actor operating under the name "Ransom Busters" is posing as an incident-recovery service to extort victims who have already been hit by ransomware. The actor contacts targets via privacy-focused email services, claiming to have infiltrated the servers of threat groups to recover files and delete stolen backups.
According to research from the GuidePoint Research and Intelligence Team (GRIT), the actor claims to have access to the infrastructure of several known threat groups, including Anubis, Settra, and DragonForce. To "resolve" the breach, Ransom Busters demands payments ranging from $20,000 to $60,000 in Bitcoin in exchange for decryption keys and the deletion of stolen data. These communications are typically conducted through non-verifiable email providers such as ProtonMail.
The Affiliate Grift
This scheme exploits the fragmented nature of the Ransomware-as-a-Service (RaaS) model. In a typical RaaS operation, primary operators provide the infrastructure and malware, while affiliates carry out the actual intrusions. This creates a chain of custody where multiple parties may have access to the same stolen data.
GRIT's investigation revealed that Ransom Busters is not a third-party researcher, but likely a ransomware affiliate working with multiple RaaS actors. Evidence shows the actor uses the same remote monitoring and management (RMM) tools, data theft methods, and internal reconnaissance techniques as the original attackers. Most tellingly, the actor shares the same backdoor account passwords used during the initial breach. GRIT assesses with moderate confidence that the actor is attempting to divert ransom payments away from the primary RaaS operators and directly into their own pockets.
Why It Matters
This tactic weaponizes a victim's desperation for recovery to secure a second, separate payment. It fundamentally undermines the already fragile trust involved in ransomware negotiations. If both the primary operator and a rogue affiliate hold copies of the stolen data, paying one party to delete the files is effectively meaningless, as the other party can still leak the information.
Justin Timothy, Principal Threat Intelligence Consultant at GuidePoint Security, emphasized the fraudulent nature of the service, stating, "A legitimate organization would not engage in criminal activity, let alone charge a fee for it."
What's Next
Security teams are advised to treat any unsolicited recovery offers from non-verified entities as extensions of the original attack. As RaaS ecosystems continue to evolve, the risk of "double-dipping" by affiliates increases. Organizations should focus on verified backup restoration and professional incident response rather than engaging with actors claiming to have "infiltrated" threat group servers.