Ransomware Affiliates Pose as Recovery Services in New Extortion Scheme
GuidePoint Security’s Research and Intelligence Team (GRIT) has identified a deceptive ransomware extortion tactic involving a group calling itself "Ransom Busters." The alleged recovery service contacts victims before their cyberattacks become public, offering to retrieve stolen files, destroy criminal backups, and provide decryption keys for a fee.
However, GRIT assesses with moderate confidence that Ransom Busters is actually a ransomware affiliate attempting to divert payments from the original ransomware operation. The scheme has been linked to incidents involving DragonForce, Settra, and Anubis ransomware activity.
How the Scam Works
Instead of relying solely on a standard ransom note, the suspected affiliate presents itself as a third-party recovery service that claims to have breached ransomware gangs’ infrastructure. Victims receive emails from "Ransom Busters LTD" targeting CEOs or IT leaders, asserting that the group has found stolen company data on ransomware servers and can delete it for a price. The emails also claim access to encryption-key storage and administrative panels.
The tactic is suspicious because legitimate cybersecurity firms typically engage with victims after an incident becomes public. Ransom Busters, however, contacts organizations while attacks are still private, suggesting prior knowledge of the breach.
Technical Evidence Links Affiliates to Multiple Ransomware Groups
GRIT analyzed two incidents where Ransom Busters approached victims and found multiple technical overlaps:
- Use of SoftPerfect Network Scanner for internal reconnaissance.
- Deployment of s5cmd to exfiltrate data to AWS cloud storage.
- Installation of Remotely (a remote monitoring tool) via PowerShell.
- Creation of a local backdoor account with the same password (Numlock!123) and hostname (DESKTOP-BBETH6K) in both intrusions.
While some indicators could reflect a shared ransomware playbook, their combined presence strengthens the correlation. GRIT noted that similar activity has appeared across multiple ransomware-as-a-service (RaaS) operations, making it unlikely that Ransom Busters is an independent recovery firm.
Financial Demands and False Promises
The group demanded $20,000 to $60,000 to delete stolen data, claiming payment was necessary to maintain access to criminal infrastructure a claim GRIT found unconvincing, as a victim’s payment would not logically secure such access.
This case highlights an evolving ransomware model, where affiliates may re-extort victims independently after stealing data. By posing as a recovery service, the actor creates an alternative payment channel while exploiting victims’ fear of exposure. There is no guarantee that criminals will delete data after payment, as they may retain copies for future extortion or leaks.
Organizations receiving unsolicited recovery offers particularly those aware of a non-public breach should treat them as likely scams or additional extortion attempts.
Source: https://cyberpress.org/ransomware-affiliate-re-extorts-victims/
DragonForce TPRM report: https://www.rankiteo.com/company/drakontas-llc
Settra TPRM report: https://www.rankiteo.com/company/provendata
"id": "drapro1787127993",
"linkid": "drakontas-llc, provendata",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'attack_vector': 'Phishing/Email (Targeting CEOs or IT leaders)',
'data_breach': {'data_encryption': 'Yes (ransomware encryption)',
'data_exfiltration': 'Yes (via s5cmd to AWS cloud storage)',
'sensitivity_of_data': 'High (potentially sensitive corporate '
'data)',
'type_of_data_compromised': 'Stolen company data, encryption '
'keys, backups'},
'description': 'GuidePoint Security’s Research and Intelligence Team (GRIT) '
'identified a deceptive ransomware extortion tactic involving '
"a group calling itself 'Ransom Busters.' The group contacts "
'victims before their cyberattacks become public, offering to '
'retrieve stolen files, destroy criminal backups, and provide '
'decryption keys for a fee. GRIT assesses with moderate '
'confidence that Ransom Busters is a ransomware affiliate '
'attempting to divert payments from the original ransomware '
'operation, linked to DragonForce, Settra, and Anubis '
'ransomware activity.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'data exposure',
'data_compromised': 'Stolen company data, encryption keys, backups',
'financial_loss': '$20,000 to $60,000 (demanded per victim)'},
'initial_access_broker': {'backdoors_established': 'Local backdoor account '
'(password: Numlock!123, '
'hostname: '
'DESKTOP-BBETH6K)',
'entry_point': 'Phishing/Email (targeting CEOs or '
'IT leaders)'},
'investigation_status': 'Ongoing (GRIT analysis)',
'lessons_learned': 'Organizations should treat unsolicited recovery offers, '
'especially those aware of a non-public breach, as likely '
'scams or additional extortion attempts. There is no '
'guarantee that criminals will delete data after payment.',
'motivation': 'Financial gain through extortion',
'post_incident_analysis': {'corrective_actions': 'Enhanced monitoring for '
'unsolicited recovery '
'offers, verification of '
'third-party recovery '
'services, and awareness of '
'affiliate-driven extortion '
'schemes.',
'root_causes': 'Use of shared ransomware affiliate '
'tools and tactics (SoftPerfect '
'Network Scanner, s5cmd, Remotely, '
'PowerShell backdoors).'},
'ransomware': {'data_encryption': 'Yes',
'data_exfiltration': 'Yes',
'ransom_demanded': '$20,000 to $60,000',
'ransomware_strain': ['DragonForce', 'Settra', 'Anubis']},
'recommendations': 'Verify the legitimacy of recovery services before '
'engaging. Assume that any unsolicited offer from a group '
'like Ransom Busters is part of an extortion scheme.',
'references': [{'source': 'GuidePoint Security’s Research and Intelligence '
'Team (GRIT)'}],
'threat_actor': 'Ransom Busters (suspected ransomware affiliate)',
'title': 'Ransomware Affiliates Pose as Recovery Services in New Extortion '
'Scheme',
'type': 'Ransomware Extortion Scheme'}