TechNewsReel
Live

Ransomware Affiliate Poses as Recovery Firm to Double-Cross Criminal Partners

A cybercriminal operating as 'Ransom Busters' is targeting victims by pretending to be a rescue service to steal payments from fellow extortionists.

TechNewsReel Newsroom · August 20, 2026

A ransomware affiliate is posing as a professional recovery service to intercept payments from victims before their data breaches become public. Operating under the name "Ransom Busters," the actor claims to have hacked ransomware gangs to retrieve encryption keys and delete stolen data, effectively acting as a third-party rescuer.

According to findings from GuidePoint Security's Research and Intelligence Team (GRIT), the entity offers to recover files and ensure data deletion for fees ranging between $20,000 and $60,000. This amount is typically significantly lower than the original ransom demands, a tactic designed to entice victims into paying the affiliate directly. GRIT assesses with moderate confidence that Ransom Busters is not a legitimate recovery firm, but rather a ransomware affiliate attempting to divert payments away from the Ransomware-as-a-Service (RaaS) operators they normally partner with.

The RaaS Betrayal

To understand this scheme, it is necessary to look at the Ransomware-as-a-Service (RaaS) model. In a standard RaaS operation, a developer creates the malware and manages the infrastructure, while an affiliate carries out the actual network intrusion. When a victim pays a ransom, the payment is typically split between the operator and the affiliate.

In this instance, the affiliate is attempting to bypass the operator entirely. By contacting the victim privately and posing as an independent recovery agent, the affiliate can keep the entire payment for themselves, effectively double-crossing their criminal partners in the ecosystem.

Technical Fingerprints

Security researchers have identified specific technical markers linking the "Ransom Busters" persona to actual intrusions. The actor reportedly used the hostname "DESKTOP-BBETH6K" and the specific password "Numlock!123" for local backdoor accounts across multiple attacks. These fingerprints have linked the actor's activity to incidents involving several different ransomware strains, including Anubis, Settra, and DragonForce.

Industry Implications

This development highlights a growing trend of internal volatility and "double-crossing" within the cybercrime underworld. For organizations currently facing an attack, it serves as a critical warning: any "recovery firm" that appears unexpectedly after a breach may actually be the original attacker attempting a second extortion attempt.

Furthermore, this scheme underscores the inherent risk of paying any entity in the ransomware ecosystem. Because the "recovery" is being offered by the criminal who likely facilitated the breach, there is no guarantee that stolen data will actually be deleted or that the encryption keys provided will be functional.

What to Watch

As RaaS affiliates become more aggressive in diverting funds, security teams should remain vigilant for unsolicited outreach from third-party recovery agents. The industry continues to monitor whether other affiliates are adopting similar "rescue" personas to undermine the traditional RaaS profit-sharing model. For now, the primary recommendation remains a distrust of any entity claiming to have "hacked" a ransomware gang on a victim's behalf.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.