CYBER-CRIME
Because apparently even ransomware gangs cannot trust the individuals they engage with
A affiliate of a ransomware group appears to have devised a novel method to extract additional payments from victims by pretending to be a recovery service and undercutting the original extortionists.
According to researchers at GuidePoint Security, a group identifying itself as “Ransom Busters” has been reaching out to ransomware victims prior to the public disclosure of their attacks, offering to decrypt files and erase stolen data for a substantially lower fee than the original ransom.
However, GuidePoint’s Research and Intelligence Team (GRIT) warns that Ransom Busters is not a vigilante collective of ransomware hunters. With moderate confidence, the team believes it is an affiliate operating across multiple ransomware‑as‑a‑service platforms, seeking to divert payments away from its actual criminal partners.
GuidePoint discovered Ransom Busters during investigations of attacks attributed to DragonForce, Settra, and Anubis. The group emailed victims, claiming to have infiltrated the ransomware gangs and located their stolen data on the criminals’ servers.
Ransom Busters asserted that it could delete the data and provide encryption keys for a modest fee ranging from $20,000 to $60,000, and it demonstrated access to the same datasets held by the ransomware affiliate responsible for the attacks, GuidePoint reported.
This raised suspicion, but the forensic evidence proved challenging to dismiss.
GuidePoint investigated two incidents where Ransom Busters contacted victims and identified a set of distinctive forensic indicators common to both. Both intrusions utilized SoftPerfect Network Scanner for reconnaissance, s5cmd to exfiltrate data to AWS cloud storage, and the Remotely remote‑management tool installed via PowerShell.
More damningly, the attacker created a local backdoor account with the password “Numlock!123” on both systems, and the same attacker‑controlled hostname, “DESKTOP-BBETH6K,” appeared in both intrusions.
While one might attribute this to shared tools or a pre‑built attack environment, GuidePoint noted that similar activity has been observed across multiple ransomware‑as‑a‑service programs, leading it to conclude that a single affiliate is likely operating for several gangs and thereby depriving its original employers of their rightful share.
GuidePoint also cautioned that paying the purported rescuers does not guarantee the disappearance of stolen information.
Consequently, if a mysterious party somehow knows you have been ransomware‑infected before you have disclosed it and generously offers to resolve the issue for $20,000, you should question how they obtained your contact information. ®


