“Ransom Busters” Scheme Likely Run by Ransomware Affiliates Themselves, GuidePoint Says

Ransom Busters extortion scheme ransomware affiliate double extortion GuidePoint

Victims of ransomware attacks are now facing an entirely new scheme: shortly after an attack, an unknown company reaches out, already aware of the stolen data, and offers – for a fee – to delete that data from the original criminals’ hands. Specialists at GuidePoint Security believe that behind these self-styled “helpers,” calling themselves Ransom Busters, lies a participant involved in several distinct criminal operations simultaneously.

Contacting Victims Before Breaches Went Public

Representatives of Ransom Busters LTD contacted organizations even before news of their respective incidents became public knowledge. In their outreach messages, senders requested to be connected with company leadership or the IT department, claiming to have located the stolen files sitting on the ransomware operators’ own servers.

Ransom Busters claimed it had discovered vulnerabilities in the criminal services’ management panels, granting it near-total control over the underlying infrastructure. The senders promised to return the stolen files, destroy any backup copies of the compromised data, and provide decryption keys. GuidePoint’s Research and Intelligence Team (GRIT) encountered this exact scheme while investigating attacks linked to DragonForce, Settra, and Anubis.

Demanding $20,000 to $60,000 to “Delete” Stolen Data

Ransom Busters demanded between $20,000 and $60,000 to delete the stolen information. Upon verification, the senders were able to prove they had access to the exact same dataset the original ransomware operator had already obtained. According to GRIT’s assessment, this awareness has a far simpler explanation: Ransom Busters is, in fact, a participant in ransomware affiliate programs attempting to siphon off a portion of the ransom from its own criminal partners.

Matching Tools Point to a Shared Actor

Two separate investigations helped researchers reach this conclusion. In both attacks, the threat actor used SoftPerfect Network Scanner to reconnoiter the network infrastructure, s5cmd to exfiltrate data to Amazon Web Services cloud storage, and the remote management tool Remotely, installed via PowerShell. Additionally, the attacker created a local account using the identical password “Numlock!123” and reused the computer name DESKTOP-BBETH6K across incidents.

The overlap of individual tools alone wouldn’t be sufficient to prove a connection between attacks. However, GuidePoint identified the exact same set of techniques appearing across incidents tied to several different ransomware affiliate programs, in every case followed by an approach from Ransom Busters. As a result, GRIT assesses with moderate confidence that these “rescue” outreach attempts trace back to a single actor operating simultaneously alongside multiple ransomware operators.

Legal Questions Surrounding the Scheme

Ransom Busters’ claims of having gained unauthorized access to criminal servers also raise significant legal concerns of their own. Such conduct could potentially fall under U.S. computer fraud and abuse law, which the Department of Justice notes separately, emphasizing that good-faith security research should never serve as cover for extorting money.

GuidePoint’s Warning to Organizations

GuidePoint warns that paying Ransom Busters offers no guarantee the data will actually be deleted. Criminals may retain additional copies, sell the information elsewhere, or demand payment again at a later date. Should an organization receive an unsolicited offer to “return” or delete stolen data in exchange for payment, it should immediately escalate the message to its incident response team and notify law enforcement authorities.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply