Ransom Busters — Rogue ransomware affiliate posing as recovery firm to intercept ransom payments

Ransom Busters (TL-2026-2074) is a high-severity ransomware operation, first published 2026-08-19. It is attributed to Ransom Busters with medium confidence, maps to 15 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2074

Threat ID
TL-2026-2074
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-08-19
Last reviewed
2026-08-19
Attribution
Ransom Busters
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
manufacturing, finance, health, technology, legal, government administration, consumer-services
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
9

Malware and tooling in Ransom Busters

Malware and tooling: anubis, Anubis RaaS, DragonForce RaaS, Remotely RMM, Settra RaaS, SoftPerfect Network Scanner, s5cmd

A suspected ransomware affiliate operating as 'Ransom Busters' contacts ransomware victims before attacks become public, offering decryption keys and stolen data deletion for $20,000–$60,000. GuidePoint Security GRIT assesses with moderate confidence that this is a single affiliate using their access to steal ransom payments from the RaaS operations they work with (DragonForce, Settra, Anubis). The scheme represents a significant escalation in third-party ransomware interference, eroding the traditional 'pay and decrypt' model by introducing an uncontrollable third party with access to victim data.

How Ransom Busters works

Ransom Busters is a fraudulent persona that contacts organizations hit by ransomware, claiming to have breached the administrative panels of the ransomware-as-a-service (RaaS) operations that attacked them. The group offers to permanently delete stolen data from ransomware group servers and provide decryption keys in exchange for $20,000 to $60,000 in Bitcoin, requesting contact with the victim's CEO or IT leadership via ProtonMail. GuidePoint Security's GRIT (Research and Intelligence Team) identified this activity through incident response engagements where the same anomalous tooling, infrastructure, and credentials appeared across two separate ransomware incidents involving different RaaS operations.

GRIT found that the attacker used identical tooling — SoftPerfect Network Scanner for network reconnaissance, s5cmd for high-performance S3-compatible cloud storage exfiltration, and Remotely (an open-source .NET remote monitoring and management tool) for persistent remote access — across incidents involving DragonForce, Settra, and Anubis ransomware. Critically, the same local backdoor account password (Numlock!123) and attacker-controlled hostname (DESKTOP-BBETH6K) appeared in both incidents, strongly indicating a single operator. GRIT assesses with moderate confidence that Ransom Busters is not a legitimate third party but rather a ransomware affiliate 'using its access to steal ransom payments from the ransomware gangs it works with,' effectively double-dipping by collecting both the RaaS affiliate commission and direct victim payments.

Coveware, a ransom negotiation and incident response firm, confirmed responding to at least one such incident where the group contacted the victim via email claiming access to both the decryption key and stolen data. Coveware distinguishes this from traditional 'ambulance chaser' recovery scams that only contact victims after public disclosure — Ransom Busters' pre-public knowledge is 'much more concerning' because paying the original ransomware operator no longer guarantees that all parties with access to the data will honor a non-disclosure agreement.

The scheme creates a trilemma for victims: pay the RaaS gang, pay Ransom Busters, or neither — with no guarantee that any party will not still leak the data. Ransom Busters claimed to have been 'breaking into the servers for over three years' and justified their fees by stating that 'acting without compensation would put their access to the threat actor's infrastructure at risk.' GRIT's principal consultant Justin Timothy noted that the possibility of a legitimate organization is 'extremely unlikely' as it would violate the U.S. Computer Fraud and Abuse Act (CFAA). At the time of publication, no confirmed victims had paid Ransom Busters, and GRIT actively discourages payment to any criminal party.

MITRE ATT&CK techniques used in TL-2026-2074

Credential Access

T1003 OS Credential Dumping

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Lateral Movement

T1021 Remote Services

Execution

T1059 Command and Scripting Interpreter; T1569 System Services

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Initial Access

T1078 Valid Accounts

Persistence

T1078 Valid Accounts; T1133 External Remote Services

Defense Evasion

T1078 Valid Accounts

Impact

T1490 Inhibit System Recovery; T1657 Financial Theft

Collection

T1560 Archive Collected Data

Exfiltration

T1567 Exfiltration Over Web Service

defense-impairment

T1685 Disable or Modify Tools

Remediation for Ransom Busters

Immediate actions

  • Engage a vetted incident response firm through established channels — do not respond to unsolicited recovery offers
  • Contact law enforcement (FBI IC3, CISA, local cybercrime unit) immediately upon receiving unsolicited recovery offers
  • Do not make payments to any party claiming to have decryption keys or stolen data without independent verification
  • Preserve all email communications from Ransom Busters for forensic analysis and law enforcement investigation

Workarounds

  • Restrict outbound S3/cloud-storage API access from internal systems to prevent s5cmd exfiltration
  • Block unauthorized RMM tools via application control policies
  • Audit local account creation and monitor for suspicious privileged account activity

Longer-term hardening

  • Implement robust incident response playbooks that include verification procedures for third-party recovery offers
  • Establish pre-vetted incident response retainer agreements with trusted firms before incidents occur
  • Deploy EDR with behavioral detection for RMM tools, network scanners, and cloud storage CLI tools
  • Monitor for known IOCs: backdoor password Numlock!123, hostname DESKTOP-BBETH6K, s5cmd/Remotely/SoftPerfect execution
  • Implement application allowlisting to block unauthorized RMM tools and cloud storage CLIs

Timeline of Ransom Busters

  • Coveware first encounters 'middlemen' contacting ransomware victims before public disclosure, using various aliases
  • Anubis ransomware first appears under the test name 'Sphinx' before rebranding, later recruiting affiliates on RAMP and XSS forums
  • DragonForce launches formal affiliate program on Russian-language RAMP forum, offering 80/20 revenue split and white-label RansomBay leak site service
  • Settra ransomware first publicly observed, posting victims on Tor-based leak site with investigative-style narratives
  • Coveware Q2 2026 report shows average ransom payment surged 176% to $1,880,612; median payment declined 50% to $150,000, driven by high-value data exfiltration extortions
  • Coveware publishes analysis of adverse cyber extortions, noting that LockBit takedown (Feb 2024) revealed retained stolen data despite deletion promises; Icarus/Klue supply chain compromise (June 2026) demonstrates payment does not guarantee data deletion
  • GRIT responds to multiple ransomware incidents where identical anomalous tooling, infrastructure, and credentials appear across DragonForce, Settra, and Anubis ransomware attacks
  • GuidePoint Security GRIT concludes with moderate confidence that Ransom Busters is a single ransomware affiliate using the persona to steal ransom payments from the RaaS operations they work with
  • BleepingComputer, Dark Reading, The Hacker News, Cybersecurity Times, and Cybersecurity Insiders publish coverage of the Ransom Busters scheme, warning the security community

Sources cited for Ransom Busters

More in ransomware

Detection coverage for TL-2026-2074

As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2074 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats