
A suspected ransomware partner poses as a ransomware recovery service called “Ransom Busters,” contacts victims before the attacks become public, and claims they can provide decryption keys and delete stolen data for a fee.
The GuidePoint Security (GRIT) Research and Intelligence Team disclosed this activity after responding to several recent ransomware attacks where victims received emails from Ransom Busters offering to help recover from the attack.
The messages were suspicious because they were sent to victims before the attacks became public, raising questions about how they even knew about the cyberattacks.
Ransom Busters said it exploited vulnerabilities in management panels used by ransomware-as-a-service (RaaS) operations to gain access to encryption keys and data stolen from victims.
The group offered to wipe the stolen data from ransomware servers, including those of DragonForce, Settra and Anubis, for $20,000 to $60,000.
However, evidence from two incidents leads GRIT to suspect that Ransom Busters is likely not a real recovery company, but rather the ransomware affiliate responsible for the attacks.
In both cases, the attackers used the same software, including SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. They also used the same tactics, including creating a local backdoor account with the password “Numlock!123” and the same attacker-controlled hostname “DESKTOP-BBETH6K.”
GRIT says it has observed overlapping activity across multiple RaaS operations and believes with moderate confidence that Ransom Busters is a single ransomware partner using its access to steal ransom payments from the ransomware gangs it works with.
GRIT told BleepingComputer that it has not seen any victims paying Ransom Busters and advises victims not to do so. However, in one Ransom Busters incident, the victim instead paid the RaaS operation behind the attack.
Researchers say the victim’s name and stolen data were not published on the ransomware operation’s data leak page, and they found no evidence that Ransom Busters exposed the stolen data outside of the RaaS environment.
Ransomware negotiator Coveware confirmed to BleepingComputer that they, too, recently responded to at least one incident in which the same group or individual contacted a victim.
“This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data,” Elizabeth Cookson, senior director of IR at Coveware, told BleepingComputer.
Coveware claims to have encountered similar “middlemen” under other names as early as 2024, but says this activity is different from the typical “ambulance chasers” who only contact victims after their attacks have been publicly disclosed.
“This type of interference in a non-public incident is much more concerning,” Lizzie told BleepingComputer.
According to Coveware, interfering with access to stolen data by a fraudulent party increases the risk to victims because paying the ransomware operation may no longer ensure that whoever has access to the data will honor an agreement not to reveal it.
The company believes that increased distrust of ransomware-as-a-service operations could lead to more of these behaviors as affiliates seek to generate additional profits outside of normal revenue-sharing arrangements with ransomware operators.
BleepingComputer has also previously warned that third-party ransomware recovery services are creating forum accounts and privately contacting victims who publicly disclose ransomware infections, claiming they can decrypt affected files.
However, these services generally targeted publicly known victims, while Ransom Busters’ knowledge of non-public incidents is far more concerning.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.


