LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Intelligence DB / Intel Report

'Ransom Busters': A Rogue Affiliate Is Re-Extorting Its Own Gangs' Victims

A threat actor calling itself Ransom Busters LTD is contacting ransomware victims before their breaches go public, posing as a recovery firm. GuidePoint Security assesses it is actually a rogue affiliate double-dipping on victims of DragonForce, Settra, and Anubis.

By Ransomware Tracker ·
Ransom BustersDragonForceSettraAnubisaffiliate fraudextortionGuidePoint SecurityRaaS
Threat Level
6/10
Sectors Targeted
professional services
manufacturing
technology

A recovery firm that isn’t

A new player has surfaced in the ransomware ecosystem, and it isn’t a ransomware group in the traditional sense. Operating under the name “Ransom Busters LTD,” the actor reaches out to organizations that have just been hit by ransomware and offers a version of a happy ending: pay a fee, and Ransom Busters will hand over working decryption keys and permanently delete the data the attackers stole.

Researchers at GuidePoint Security’s Research and Intelligence Team (GRIT) assess with moderate confidence that Ransom Busters is not an independent recovery outfit at all. It is a ransomware affiliate — someone with direct, insider access to active RaaS intrusions — attempting to intercept extortion payments before the group it works for can collect them. In effect, an affiliate is running a second extortion scheme against its own employer’s victims, and pocketing the proceeds itself.

How the pitch works

The tell that first caught researchers’ attention is timing. Ransom Busters contacts victims before their incidents become public — a level of insider knowledge that a genuine third-party recovery firm would have no way to obtain. Outreach is aimed at chief executives or IT leadership directly, and the pitch is consistent: the sender claims to have compromised the ransomware operators’ own infrastructure, discovered the victim’s stolen files sitting on that infrastructure, and is now offering to delete the copies and hand over decryption material — for a fee between $20,000 and $60,000, generally well below the original ransom demand.

It is a plausible-sounding offer built to exploit a victim already in crisis mode, weighing options, and eager for any path that looks cheaper and faster than negotiating with the original attacker. GuidePoint’s warning is blunt: paying an unknown intermediary provides no actual assurance that stolen data is deleted, that any encryption keys provided are genuine, or that the underlying attacker — or the rogue affiliate itself — no longer has access to the network.

The forensic fingerprint linking the cases

GuidePoint examined multiple intrusions where Ransom Busters approached victims and found the underlying attacks traced back to three separate RaaS brands: DragonForce, Settra, and Anubis. Despite the different ransomware labels on the encryptor and leak-site branding, the intrusions investigated shared a strikingly consistent operational fingerprint, strongly suggesting a single individual or small crew working as an affiliate across more than one program simultaneously:

  • SoftPerfect Network Scanner used for internal network reconnaissance
  • s5cmd used to exfiltrate stolen data to attacker-controlled AWS storage
  • Remotely, a legitimate remote-management tool, deployed via PowerShell for persistence
  • An identical backdoor credential — the password “Numlock!123” — reused across incidents
  • A matching attacker-side hostname, “DESKTOP-BBETH6K”, observed in more than one intrusion

That combination of reused tooling, a shared password, and an identical hostname is the kind of operational fingerprint that rarely survives across genuinely unrelated actors. It points to the same person conducting the intrusion, exfiltration, and later “recovery firm” outreach — playing both the attacker and the fake rescuer in the same incident.

What this signals about the affiliate economy

RaaS affiliate models depend on trust that is inherently fragile: affiliates get a cut (often 70-90%) of the ransom, but the core operators control the leak site, the negotiation portal, and — crucially — the payment channel. Ransom Busters represents a logical, if novel, failure mode of that arrangement. An affiliate with hands-on access to a victim’s stolen data and encryption material has no technical barrier stopping them from cutting out the operator entirely and running a private, parallel extortion track — collecting the full amount rather than a percentage-based split.

GuidePoint found no confirmed cases of a victim actually paying Ransom Busters directly, though at least one of the victims examined did pay the underlying ransomware operation through the normal channel instead. No evidence emerged that stolen data was leaked outside the original RaaS environment as a result of this scheme. Even so, the pattern is a warning sign for incident responders and negotiators: any unsolicited outside offer referencing details of a not-yet-public breach should be treated as a second extortion attempt, not a rescue.

Recommendations

Organizations responding to a ransomware incident should validate any external contact claiming insider access to the attacker’s infrastructure through their negotiator or incident response firm before engaging, and should assume that any party offering a discounted “delete and decrypt” deal outside the established negotiation channel has no verifiable ability to make good on the promise. As affiliate-model RaaS continues to fragment across dozens of active brands, expect further blurring between “attacker” and “opportunist” roles within the same intrusion.

// Related Intelligence
Intel Report

Qilin's 443% Surge: Inside the RaaS Operation Now Leading the 2026 Ransomware Market

Intel Report

Ransomware Targeting Financial Services: 2026 Sector Intelligence Report

Intel Report

Ransomware Negotiation in 2026: Tactics, Timelines, and When Not to Pay