A new threat actor known as 'Ransom Busters' is deceiving ransomware victims by offering fake data recovery services. The group aims to divert ransom payments into their own pockets.

  • 'Ransom Busters' is posing as a legitimate incident-recovery service.
  • The group claims to have access to encryption keys and criminal servers.
  • They are demanding between $20,000 and $60,000 to 'delete' stolen data.

In a sophisticated twist to the ongoing ransomware epidemic, a new malicious entity calling itself 'Ransom Busters' has emerged. According to the GuidePoint Research and Intelligence Team (GRIT), these actors are approaching victims of cyberattacks with a deceptive offer: helping them recover their files and destroying the stolen data held by criminals. However, intelligence suggests this is not a rescue mission, but a calculated attempt to hijack extortion negotiations.

The attackers claim to have infiltrated the administrative panels of various Ransomware-as-a-Service (RaaS) groups, such as DragonForce, Settra, and Anubis. By claiming access to encryption keys, they offer a 'solution' to victims for a fee ranging from $20,000 to $60,000. This tactic, while appearing helpful, is actually an attempt by a ransomware affiliate to monetize victims outside the traditional RaaS structure.

Why This Matters

BozokMedia analysis shows that this evolution in cybercrime represents a shift toward 'inter-criminal extortion.' Instead of just attacking a company, criminals are now attacking the financial flow of other criminal organizations. This creates a chaotic environment for victims, who may find themselves paying multiple parties for the same 'service' of data suppression, with no guarantee that the data is actually deleted.

'Ransom Busters' activity directly damages the credibility and revenue potential of the RaaS operations they are affiliated with.

Cybersecurity experts have identified several major red flags. Unlike legitimate Incident Response (IR) firms, Ransom Busters reaches out before an attack is even public knowledge. Furthermore, they use privacy-focused email services like ProtonMail rather than professional corporate domains and demand payment exclusively in Bitcoin—a hallmark of criminal activity rather than legitimate business.

Comparison: Legitimate IR vs. Ransom Busters

FeatureLegitimate IR FirmRansom Busters (Suspected)
Timing of ContactAfter incident disclosureMid-incident/Pre-disclosure
Email DomainCorporate (@company.com)Privacy-focused (ProtonMail)
Pricing ModelPost-scoping assessmentImmediate financial demand
Payment MethodStandard Invoicing/BankingCryptocurrency (Bitcoin)

The GRIT team's assessment suggests that Ransom Busters is likely a single ransomware affiliate working across multiple groups. By using the same tools and tactics, they are attempting to divert the victim's attention and funds away from the original attackers. This creates a 'double-dip' scenario where the victim's ability to verify data destruction becomes nearly impossible.

Did You Know?: In many RaaS models, affiliates do not have full control over the stolen data, making any third-party claim of 'data deletion' highly unverifiable.

Frequently Asked Questions

1. How can I identify a fake recovery service?
Be wary of any service that demands Bitcoin, uses free email providers, or provides a price quote before understanding the scope of your technical incident.

2. Is it safe to pay 'Ransom Busters' to delete my data?
No. There is no way to ensure that all copies of your data have been destroyed, especially if the person claiming to delete it is part of the original criminal ecosystem.