#ransombusters
Ransomware Affiliate Pretends to be Recovery Service for Extortion #CyberSecurity #Extortion #RansomBusters
Ransomware Affiliate Pretends to be Recovery Service for Extortion
An alleged ransomware affiliate is pretending to be a ransomware recovery service named “Ransom Busters,” reaching out to victims before the attacks become public and claims it can delete stolen data and provide decryption keys for some fees. Fake ransomware recovery service The activity was discovered by GuidePoint Security’s Research and Intelligence Team (GRIT) after it responded to various cases where targets got emails apparently from Ransom Busters, contacting to provide help in recovering from the ransomware attack.  This seems suspicious because cybersecurity firms usually contact ransomware victims to offer recovery services or consulting after the attack has happened and becomes public knowledge. But in this case, Ransom Busters’ knowledge about the attack that was not yet public raises questions. GRIT believes Ransom Busters to be working across various ransomware operations, and have taken a new extortion approach.  The group contacted victims via emails, requesting to get in touch with their CEO or IT leadership.  According to GRIT, the email said “I am a representative of a project that assists victims of cyberattacks. We have been identifying vulnerabilities and infiltrating the servers of criminal groups for over three years. On the server we recently accessed, we discovered data stolen from your company [...] We can return your files to you and destroy all backups held by the group. Additionally, we have gained access to the encryption key storage and can help you regain access to your encrypted files.” Extortion tactic In the communications after this mail, Ransom Busters said they found the flaws in the admin panels of various ransomware-as-a-service (RaaS) operations. It offered to remove the stolen data from ransomware servers such as Settra, DragonForce, and Anubis, for a fee of $20,000 to $60,000. But evidence from the two incidents has led GRIT to suspect that Ransom Busters is the group responsible for the attacks. In both incidents, the threat actors used the same software such as s5cmd, Remotely remote monitoring tool, and SoftPerfect Network Scanner. The group also used the same approach to create a local backdoor account via the same threat actor-controlled hostname 'DESKTOP-BBETH6K' and password Numlock!123'.  The attacker claimed this access gave them command over “almost all of their infrastructure,” according to GRIT. The aim of Ransom Busters seems to be financial, like other RaaS groups. Impact on ransomware victims Ransomware groups such as Ransom Busters cannot be trusted as they use deceptive tactics for extortion payments. In these incidents, it is observed that even payments to these gangs does not guarantee recovery of stolen data and if it will be deleted. If your organization receives such mails, it should be immediately reported to the response team.
dlvr.it
September 9, 2026 at 2:25 PM
📢 Ransom Busters : un affilié ransomware se fait passer pour un sauveur bienveillant

Cet article présente les conclusions de l'équipe GRIT suite à plusieurs interventions en réponse à incidents impliquant une entité inconnue…

🟡 vérification factuelle moyenne
#RansomBusters #affilié #Cyberveille
Ransom Busters : un affilié ransomware se fait passer pour un sauveur bienveillant
Cet article présente les conclusions de l'équipe GRIT suite à plusieurs interventions en réponse à incidents impliquant une entité inconnue se présentant sous le nom "Ransom Busters LTD".
cyberveille.ch
August 20, 2026 at 2:30 PM
Ransomware affiliate impersonates a recovery firm, contacting victims before attacks go public to offer decryption and data deletion for payment. GRIT and Coveware link the scheme to DragonForce, Settra, and Anubis. #RansomBusters #DragonForce
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is impersonating a recovery service called Ransom Busters, emailing victims before attacks are public and claiming it can provide decryption keys and erase stolen data for a fee. GRIT and Coveware believe the activity may be tied to the same affiliate behind attacks involving DragonForce, Settra, and Anubis, using overlapping tools and tactics to extort victims and siphon ransom payments. #RansomBusters #DragonForce #Settra #Anubis
www.hendryadrian.com
August 19, 2026 at 11:30 PM
Ransom Busters is contacting victims before public disclosure, claiming access to ransomware servers and demanding $20,000 to $60,000 to delete stolen data. GuidePoint links the activity to a growing industrialized extortion ecosystem. #RansomBusters
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
Ransom Busters is a deceptive ransomware affiliate that directly contacts victims, claims to have accessed ransomware group servers, and demands $20,000 to $60,000 to delete stolen data. GuidePoint also linked the broader ransomware landscape to UNC6671, rising extortion brands, and increasingly industrialized tactics such as phishing, AitM operations, and pre-encryption access...
www.hendryadrian.com
August 19, 2026 at 4:45 AM