A ransomware affiliate operating under the name Ransom Busters has been observed sending unsolicited emails to organizations that have been victims of ransomware attacks. The group claims to have successfully infiltrated the servers of various ransomware-as-a-service (RaaS) operations.
In these communications, Ransom Busters offers to delete data stolen from the victim company that is purportedly held on the compromised ransomware servers. This service is offered in exchange for a fee ranging from $20,000 to $60,000.
Cybersecurity firm GuidePoint Research and Intelligence Team (GRIT) highlighted the unusual nature of this approach. While cybersecurity companies commonly offer recovery services to ransomware victims, they typically do so after an attack becomes public knowledge, not proactively as a third party claiming to have breached the attackers' infrastructure.
Ransom Busters requests contact with the victim's CEO or IT leadership, asserting that they have exploited vulnerabilities in RaaS administrative panels and have maintained access to these servers for over three years.
GuidePoint has encountered Ransom Busters' modus operandi in incidents involving threat groups such as DragonForce, Settra, and Anubis. The cybersecurity firm deems it highly improbable that this operation is legitimate, noting that such actions could violate the U.S. Computer Fraud Abuse Act.
Justin Timothy, a Principal Consultant at GRIT, suggested that the operators are either concealing the true origin of their access or operating outside legal boundaries. When questioned about their fee, the group provided an explanation that charging for their help was necessary to protect their access to the threat actor's infrastructure.
Analysis of two separate incidents where Ransom Busters contacted victims revealed consistent tactics and tools. These include the use of SoftPerfect Network Scanner for internal reconnaissance, s5cmd for exfiltrating data to cloud storage via AWS, and Remotely for remote monitoring and management.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A ransomware affiliate, operating under the name "Ransom Busters," is contacting victims of ransomware attacks before they become public, offering decryption keys and data deletion for a fee. GuidePoint Security's Research and Intelligence Team (GRIT) believes this entity is the original attacker attempting to intercept ransom payments from both victims and the ransomware-as-a-service (RaaS) operations it works with. This activity highlights an evolving tactic within the ransomware ecosystem where affiliates are attempting to double-extort victims and defraud their RaaS partners.
A ransomware affiliate named Ransom Busters is emailing victims, claiming to have hacked ransomware group servers and offering to delete stolen data for $20,000 to $60,000. This activity is unusual as it involves a third party proactively contacting victims with an offer to recover data and delete backups held by ransomware groups. The practice raises legal concerns under the U.S. Computer Fraud Abuse Act.