Ransom Busters — Rogue ransomware affiliate posing as recovery firm to intercept ransom payments
Ransom Busters (TL-2026-2074) is a high-severity ransomware operation, first published 2026-08-19. It is attributed to Ransom Busters with medium confidence, maps to 15 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2074
- Threat ID
- TL-2026-2074
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-08-19
- Last reviewed
- 2026-08-19
- Attribution
- Ransom Busters
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, finance, health, technology, legal, government administration, consumer-services
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in Ransom Busters
Malware and tooling: anubis, Anubis RaaS, DragonForce RaaS, Remotely RMM, Settra RaaS, SoftPerfect Network Scanner, s5cmd
A suspected ransomware affiliate operating as 'Ransom Busters' contacts ransomware victims before attacks become public, offering decryption keys and stolen data deletion for $20,000–$60,000. GuidePoint Security GRIT assesses with moderate confidence that this is a single affiliate using their access to steal ransom payments from the RaaS operations they work with (DragonForce, Settra, Anubis). The scheme represents a significant escalation in third-party ransomware interference, eroding the traditional 'pay and decrypt' model by introducing an uncontrollable third party with access to victim data.
How Ransom Busters works
Ransom Busters is a fraudulent persona that contacts organizations hit by ransomware, claiming to have breached the administrative panels of the ransomware-as-a-service (RaaS) operations that attacked them. The group offers to permanently delete stolen data from ransomware group servers and provide decryption keys in exchange for $20,000 to $60,000 in Bitcoin, requesting contact with the victim's CEO or IT leadership via ProtonMail. GuidePoint Security's GRIT (Research and Intelligence Team) identified this activity through incident response engagements where the same anomalous tooling, infrastructure, and credentials appeared across two separate ransomware incidents involving different RaaS operations.
GRIT found that the attacker used identical tooling — SoftPerfect Network Scanner for network reconnaissance, s5cmd for high-performance S3-compatible cloud storage exfiltration, and Remotely (an open-source .NET remote monitoring and management tool) for persistent remote access — across incidents involving DragonForce, Settra, and Anubis ransomware. Critically, the same local backdoor account password (Numlock!123) and attacker-controlled hostname (DESKTOP-BBETH6K) appeared in both incidents, strongly indicating a single operator. GRIT assesses with moderate confidence that Ransom Busters is not a legitimate third party but rather a ransomware affiliate 'using its access to steal ransom payments from the ransomware gangs it works with,' effectively double-dipping by collecting both the RaaS affiliate commission and direct victim payments.
Coveware, a ransom negotiation and incident response firm, confirmed responding to at least one such incident where the group contacted the victim via email claiming access to both the decryption key and stolen data. Coveware distinguishes this from traditional 'ambulance chaser' recovery scams that only contact victims after public disclosure — Ransom Busters' pre-public knowledge is 'much more concerning' because paying the original ransomware operator no longer guarantees that all parties with access to the data will honor a non-disclosure agreement.
The scheme creates a trilemma for victims: pay the RaaS gang, pay Ransom Busters, or neither — with no guarantee that any party will not still leak the data. Ransom Busters claimed to have been 'breaking into the servers for over three years' and justified their fees by stating that 'acting without compensation would put their access to the threat actor's infrastructure at risk.' GRIT's principal consultant Justin Timothy noted that the possibility of a legitimate organization is 'extremely unlikely' as it would violate the U.S. Computer Fraud and Abuse Act (CFAA). At the time of publication, no confirmed victims had paid Ransom Busters, and GRIT actively discourages payment to any criminal party.
MITRE ATT&CK techniques used in TL-2026-2074
Credential Access
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery
Lateral Movement
Execution
T1059 Command and Scripting Interpreter; T1569 System Services
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools
Initial Access
Persistence
T1078 Valid Accounts; T1133 External Remote Services
Defense Evasion
Impact
T1490 Inhibit System Recovery; T1657 Financial Theft
Collection
Exfiltration
T1567 Exfiltration Over Web Service
defense-impairment
Remediation for Ransom Busters
Immediate actions
- Engage a vetted incident response firm through established channels — do not respond to unsolicited recovery offers
- Contact law enforcement (FBI IC3, CISA, local cybercrime unit) immediately upon receiving unsolicited recovery offers
- Do not make payments to any party claiming to have decryption keys or stolen data without independent verification
- Preserve all email communications from Ransom Busters for forensic analysis and law enforcement investigation
Workarounds
- Restrict outbound S3/cloud-storage API access from internal systems to prevent s5cmd exfiltration
- Block unauthorized RMM tools via application control policies
- Audit local account creation and monitor for suspicious privileged account activity
Longer-term hardening
- Implement robust incident response playbooks that include verification procedures for third-party recovery offers
- Establish pre-vetted incident response retainer agreements with trusted firms before incidents occur
- Deploy EDR with behavioral detection for RMM tools, network scanners, and cloud storage CLI tools
- Monitor for known IOCs: backdoor password Numlock!123, hostname DESKTOP-BBETH6K, s5cmd/Remotely/SoftPerfect execution
- Implement application allowlisting to block unauthorized RMM tools and cloud storage CLIs
Timeline of Ransom Busters
- Coveware first encounters 'middlemen' contacting ransomware victims before public disclosure, using various aliases
- Anubis ransomware first appears under the test name 'Sphinx' before rebranding, later recruiting affiliates on RAMP and XSS forums
- DragonForce launches formal affiliate program on Russian-language RAMP forum, offering 80/20 revenue split and white-label RansomBay leak site service
- Settra ransomware first publicly observed, posting victims on Tor-based leak site with investigative-style narratives
- Coveware Q2 2026 report shows average ransom payment surged 176% to $1,880,612; median payment declined 50% to $150,000, driven by high-value data exfiltration extortions
- Coveware publishes analysis of adverse cyber extortions, noting that LockBit takedown (Feb 2024) revealed retained stolen data despite deletion promises; Icarus/Klue supply chain compromise (June 2026) demonstrates payment does not guarantee data deletion
- GRIT responds to multiple ransomware incidents where identical anomalous tooling, infrastructure, and credentials appear across DragonForce, Settra, and Anubis ransomware attacks
- GuidePoint Security GRIT concludes with moderate confidence that Ransom Busters is a single ransomware affiliate using the persona to steal ransom payments from the RaaS operations they work with
- BleepingComputer, Dark Reading, The Hacker News, Cybersecurity Times, and Cybersecurity Insiders publish coverage of the Ransom Busters scheme, warning the security community
Sources cited for Ransom Busters
- Rogue ransomware affiliate poses as recovery firm to steal payments
- 'Ransom Busters': Ransomware Actor Poses as Recovery Service
- Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
- Ransomware Affiliates Adopt Fake Recovery Services as New Extortion Revenue Stream
- Ransomware victims being duped with fake Ransom Buster Email Communication
- Coveware by Veeam — Cyber Extortion Payment Trends Q2 2026
- DragonForce Ransomware — Threat Profile and Technical Analysis
- Anubis Ransomware Threat Profile — Vali Cyber
- Settra Ransomware — MOXFIVE Threat Analysis
- CISA — FiveHands Ransomware Analysis Report (AR21-126A)
- Coveware Q1 2026 Ransomware Report
More in ransomware
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
Detection coverage for TL-2026-2074
As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2074 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.