← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Ransom Busters Affiliate Claims Hacking Ransomware Servers, Demands Payment from Victims

🔄 Updated 4h ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Ransom Busters contacts ransomware victims directly via email.
  • The group claims to have hacked ransomware-as-a-service (RaaS) servers.
  • Payments of $20,000-$60,000 are requested to delete stolen data.
  • The activity is considered highly unlikely to be legitimate and potentially illegal.
  • Ransom Busters contacts victims before attacks become public.
  • GuidePoint Security's Research and Intelligence Team (GRIT) disclosed this activity.
  • GRIT believes Ransom Busters is the original attacker.
  • Ransom Busters offered to delete data from DragonForce, Settra, and Anubis servers.

New Ransomware Affiliate Tactic Emerges

A ransomware affiliate operating under the name Ransom Busters has been observed sending unsolicited emails to organizations that have been victims of ransomware attacks. The group claims to have successfully infiltrated the servers of various ransomware-as-a-service (RaaS) operations.

In these communications, Ransom Busters offers to delete data stolen from the victim company that is purportedly held on the compromised ransomware servers. This service is offered in exchange for a fee ranging from $20,000 to $60,000.

Anomalous Recovery Offer

Cybersecurity firm GuidePoint Research and Intelligence Team (GRIT) highlighted the unusual nature of this approach. While cybersecurity companies commonly offer recovery services to ransomware victims, they typically do so after an attack becomes public knowledge, not proactively as a third party claiming to have breached the attackers' infrastructure.

Ransom Busters requests contact with the victim's CEO or IT leadership, asserting that they have exploited vulnerabilities in RaaS administrative panels and have maintained access to these servers for over three years.

Legal and Operational Concerns

GuidePoint has encountered Ransom Busters' modus operandi in incidents involving threat groups such as DragonForce, Settra, and Anubis. The cybersecurity firm deems it highly improbable that this operation is legitimate, noting that such actions could violate the U.S. Computer Fraud Abuse Act.

Justin Timothy, a Principal Consultant at GRIT, suggested that the operators are either concealing the true origin of their access or operating outside legal boundaries. When questioned about their fee, the group provided an explanation that charging for their help was necessary to protect their access to the threat actor's infrastructure.

Tools and Tactics

Analysis of two separate incidents where Ransom Busters contacted victims revealed consistent tactics and tools. These include the use of SoftPerfect Network Scanner for internal reconnaissance, s5cmd for exfiltrating data to cloud storage via AWS, and Remotely for remote monitoring and management.

Updates

🕒 2026-08-19 · new reporting from BleepingComputer
  • Ransom Busters contacts victims before attacks become public.
  • GuidePoint Security's Research and Intelligence Team (GRIT) disclosed this activity.
  • GRIT believes Ransom Busters is the original attacker.
  • Ransom Busters offered to delete data from DragonForce, Settra, and Anubis servers.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~28 min · 23 stories · Aug 19

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A ransomware affiliate, operating under the name "Ransom Busters," is contacting victims of ransomware attacks before they become public, offering decryption keys and data deletion for a fee. GuidePoint Security's Research and Intelligence Team (GRIT) believes this entity is the original attacker attempting to intercept ransom payments from both victims and the ransomware-as-a-service (RaaS) operations it works with. This activity highlights an evolving tactic within the ransomware ecosystem where affiliates are attempting to double-extort victims and defraud their RaaS partners.

A ransomware affiliate named Ransom Busters is emailing victims, claiming to have hacked ransomware group servers and offering to delete stolen data for $20,000 to $60,000. This activity is unusual as it involves a third party proactively contacting victims with an offer to recover data and delete backups held by ransomware groups. The practice raises legal concerns under the U.S. Computer Fraud Abuse Act.