TechNewsReel
Live

Ransomware Affiliate Exposed Running 'Ransom Busters' Recovery Scam

Security researchers find a rogue insider posing as a rescue service to steal additional fees from ransomware victims.

TechNewsReel Newsroom · August 18, 2026

A threat actor operating under the moniker 'Ransom Busters' has been targeting ransomware victims with a fraudulent recovery scheme, claiming to have breached criminal servers to retrieve stolen data. The operator cold-emails victims, offering to provide encryption keys and delete leaked files in exchange for payments ranging from $20,000 to $60,000 in Bitcoin.

Security researchers from GuidePoint Research (GRIT) have identified the operation as a deceptive "side scam" run by a ransomware affiliate. According to GRIT, the activity was observed across attacks tied to the DragonForce, Settra, and Anubis ransomware groups. The researchers linked the fraudulent activity to a single operator by identifying identical internal reconnaissance software, backdoor passwords, and attacker-controlled hostnames used across multiple victims.

The Insider Threat

This scheme exploits the Ransomware-as-a-Service (RaaS) business model. In a typical RaaS structure, a core developer provides the ransomware tools, while affiliates handle the actual infiltration and deployment of the malware. In this instance, an affiliate is leveraging their existing access to victim systems to pose as a neutral third-party rescue service. By pretending to be an ally who has "hacked" the main gang, the affiliate attempts to divert a portion of the ransom payments for personal gain before the primary criminal organization can collect.

Why It Matters

This development adds a dangerous layer of deception to the ransomware ecosystem. Victims, desperate to recover their data or prevent a public leak, may be tempted to pay a smaller "recovery fee" to a perceived savior. However, because the core RaaS gang typically maintains its own copies of the stolen data, these payments offer no real security.

Justin Timothy, a principal threat intelligence consultant at GuidePoint, warns that if both the main gang and the Ransom Busters operator hold the stolen files, any payment made for data suppression is "effectively worthless." Paying the affiliate does not guarantee that the primary attackers will not still leak the data or demand their own ransom.

What's Next

Organizations currently facing ransomware attacks are urged to exercise extreme caution when contacted by unsolicited "recovery services." Security professionals should treat any one-off offers to retrieve keys via third parties as high-risk fraudulent activity. As RaaS affiliates continue to find ways to monetize their access independently of the core gangs, the industry expects to see more sophisticated social engineering attempts targeting the vulnerability and desperation of breached companies.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.