Ransom Busters — Rogue ransomware affiliate posing as recovery firm to intercept ransom payments — Threadlinqs Intelligence
As of 2026-08-19, Ransom Busters — Rogue ransomware affiliate posing as recovery firm to intercept ransom payments is a high-severity ransomware threat attributed to Ransom Busters, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 9 indicators of compromise.
Threat ID: TL-2026-2074 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Ransom Busters · FINANCIAL
A suspected ransomware affiliate operating as 'Ransom Busters' contacts ransomware victims before attacks become public, offering decryption keys and stolen data deletion for $20,000–$60,000.
Ransom Busters is a fraudulent persona that contacts organizations hit by ransomware, claiming to have breached the administrative panels of the ransomware-as-a-service (RaaS) operations that attacked them. The group offers to permanently delete stolen data from ransomware group servers and provide decryption keys in exchange for $20,000 to $60,000 in Bitcoin, requesting contact with the victim's CEO or IT leadership via ProtonMail. GuidePoint Security's GRIT (Research and Intelligence Team) identified this activity through incident response engagements where the same anomalous tooling, infrastructure, and credentials appeared across two separate ransomware incidents involving different RaaS operations.
GRIT found that the attacker used identical tooling — SoftPerfect Network Scanner for network reconnaissance, s5cmd for high-performance S3-compatible cloud storage exfiltration, and Remotely (an open-source .NET remote monitoring and management tool) for persistent remote access — across incidents involving DragonForce, Settra, and Anubis ransomware. Critically, the same local backdoor account password (Numlock!123) and attacker-controlled hostname (DESKTOP-BBETH6K) appeared in both incidents, strongly indicating a single operator. GRIT assesses with moderate confidence that Ransom Busters is not a legitimate third party but rather a ransomware affiliate 'using its access to steal ransom payments from the ransomware gangs it works with,' effectively double-dipping by collecting both the RaaS affiliate commission and direct victim payments.
Coveware, a ransom negotiation and incident response firm, confirmed responding to at least one such incident where the group contacted the victim via email claiming access to both the decryption key and stolen data. Coveware distinguishes this from traditional 'ambulance chaser' recovery scams that only contact victims after public disclosure — Ransom Busters' pre-public knowledge is 'much more concerning' because paying the original ransomware operator no longer guarantees that all parties with access to the data will honor a non-disclosure agreement.
The scheme creates a trilemma for victims: pay the RaaS gang, pay Ransom Busters, or neither — with no guarantee that any party will not still leak the data. Ransom Busters claimed to have been 'breaking into the servers for over three years' and justified their fees by stating that 'acting without compensation would put their access to the threat actor's infrastructure at risk.' GRIT's principal consultant Justin Timothy noted that the possibility of a legitimate organization is 'extremely unlikely' as it would violate the U.S. Computer Fraud and Abuse Act (CFAA). At the time of publication, no confirmed victims had paid Ransom Busters, and GRIT actively discourages payment to any criminal party.
Target sectors: manufacturing, finance, health, technology, legal, government administration, consumer-services
Target regions: North America, Europe, Asia-Pacific
Timeline
- Coveware first encounters 'middlemen' contacting ransomware victims before public disclosure, using various aliases
- Anubis ransomware first appears under the test name 'Sphinx' before rebranding, later recruiting affiliates on RAMP and XSS forums
- DragonForce launches formal affiliate program on Russian-language RAMP forum, offering 80/20 revenue split and white-label RansomBay leak site service
- Settra ransomware first publicly observed, posting victims on Tor-based leak site with investigative-style narratives
- Coveware Q2 2026 report shows average ransom payment surged 176% to $1,880,612; median payment declined 50% to $150,000, driven by high-value data exfiltration extortions
- Coveware publishes analysis of adverse cyber extortions, noting that LockBit takedown (Feb 2024) revealed retained stolen data despite deletion promises; Icarus/Klue supply chain compromise (June 2026) demonstrates payment does not guarantee data deletion
- GRIT responds to multiple ransomware incidents where identical anomalous tooling, infrastructure, and credentials appear across DragonForce, Settra, and Anubis ransomware attacks
- GuidePoint Security GRIT concludes with moderate confidence that Ransom Busters is a single ransomware affiliate using the persona to steal ransom payments from the RaaS operations they work with
- BleepingComputer, Dark Reading, The Hacker News, Cybersecurity Times, and Cybersecurity Insiders publish coverage of the Ransom Busters scheme, warning the security community
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 9 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1078, T1059, T1569, T1078, T1133, T1078, T1685, T1003, T1046, T1018