
Ransomware Affiliate Poses as Recovery Firm to Steal Ransom Payments
.webp)
A ransomware affiliate has been posing as a specialist rescue outfit and contacting victims before their attacks became public. Researchers describe the operation as a ransomware recovery scam that drains payments away from the criminal groups the affiliate works for. The entity calls itself Ransom Busters LTD.
It emailed corporate addresses at several breached companies and offered to delete stolen files and supply decryption keys for fees between $20,000 and $60,000. GuidePoint Security assesses with moderate confidence that the sender is one of the attackers behind those intrusions. That assessment turns an apparent lifeline into a recovery scam run by the same people who caused the damage.
How the ransomware recovery scam reached victims first
The emails arrived at domain addresses inside victim organisations. Each one asked the recipient to forward it to the CEO or IT leadership. The sender described itself as a project that assists victims of cyberattacks. It claimed more than three years of experience finding vulnerabilities in criminal servers and infiltrating them.
The pitch got specific from there. The sender said it had located data stolen from the recipient's company on a server it had recently accessed. It offered to return those files. It also offered to destroy every backup the gang held and use its access to encryption key storage to unlock affected systems.
Security firms do approach ransomware victims with consulting and recovery offers. But they wait until a leak site listing appears or the company discloses the incident itself. Nobody outside an attack knows about a breach before that moment. That timing turned a helpful-sounding email into a suspected ransomware recovery scam.
Tooling overlap points to a single affiliate
Forensic work is what separates a plausible offer from a documented ransomware recovery scam. GuidePoint's digital forensics team examined two incidents where the group made contact, and both environments carried the same fingerprints.
The attackers ran SoftPerfect Network Scanner for internal reconnaissance. They moved stolen data to AWS cloud storage with the s5cmd utility. They also installed the Remotely remote monitoring tool through a PowerShell script.
Two further details carried more weight than the tooling. In both intrusions the attacker created a local backdoor account with the identical password, Numlock!123. Both cases also traced back to the same attacker-controlled hostname, DESKTOP-BBETH6K. Password choice has no constraints, so reusing one across separate victims makes for a strong correlation.
The same persona surfaced in incidents involving DragonForce, Settra and Anubis. Those are three distinct ransomware-as-a-service operations. Shared tooling can point to a standardised playbook handed to affiliates inside one programme. Activity spanning three separate programmes fits a different explanation, and researchers settled on a single affiliate working across all of them.
Why this scam changes the payment calculus
Double extortion rests on a promise that barely survives scrutiny. Victims pay because the gang says it will delete what it took. A rogue party holding a second copy of that data breaks the promise outright.
Settling with the operation no longer accounts for everyone who has the files. A ransomware recovery scam running in parallel with a live negotiation leaves the victim paying twice for nothing.
The negotiation firm Coveware responded to at least one incident involving the same actor. Elizabeth Cookson, Senior Director of IR at the company, said the third party emailed the victim and claimed access to both the decryption key and the stolen data. Coveware has tracked similar middlemen under other names as far back as 2024. It draws a hard line between those cases and this one, because a recovery scam that lands during a non-public ransomware incident signals far deeper access.
No victim has paid Ransom Busters, as far as researchers can tell. In one case the victim paid the ransomware operation instead. Its name and data never appeared on the leak site, and investigators found no sign that the affiliate leaked the files elsewhere. That outcome rested entirely on a criminal's goodwill.
The legal problem underneath the offer
Breaking into a criminal group's servers to delete data would likely fall foul of the Computer Fraud and Abuse Act. A legitimate firm does not commit a federal offence and then invoice for it. Researchers pressed the group on why it charged at all.
The answer was that acting for free would put its access to criminal infrastructure at risk, an explanation with no logical connection to the fee. The invoice is the clearest tell in this ransomware recovery scam.
Spotting a ransomware recovery scam during an active incident
Anyone targeted by a ransomware recovery scam meets it at the worst possible moment, with systems down and pressure building. Treat unexpected contact as part of the attack. Route the message to the incident response team straight away and preserve it as evidence instead of replying. A sender who knows about a breach nobody has announced is either involved in it or holds the data taken during it.
Law enforcement and established response firms remain the reliable route through a ransomware incident. Verify anyone claiming to represent a security company through channels you found yourself. Never use the contact details supplied in the email. Treat any guarantee of data deletion as unenforceable, because no payment to a criminal party comes with proof that copies no longer exist.
Distrust inside ransomware-as-a-service operations may produce more of this behaviour. Affiliates have every reason to look for income outside the revenue splits their employers set. So the ransomware recovery scam running under the Ransom Busters name reads less like an isolated curiosity and more like a preview. Anyone willing to defraud the criminal enterprise paying them has already answered the question of what a victim's data is worth to them.
Subscribe to receive the latest blog posts to your inbox every week.