'Ransom Busters' Isn't Here to Help: Researchers Say the Fake Rescue Service Is Just Another Ransomware Play

'Ransom Busters' Isn't Here to Help: Researchers Say the Fake Rescue Service Is Just Another Ransomware Play

'Ransom Busters' Isn't Here to Help: Researchers Say the Fake Rescue Service Is Just Another Ransomware Play

A group calling itself "Ransom Busters" has been emailing ransomware victims with an offer that sounds almost heroic: pay us $20,000 to $60,000 and we will break into the attackers' servers, delete your stolen data, and hand back your encryption keys. GuidePoint Research and Intelligence Team (GRIT) says the whole thing is a con run by a ransomware affiliate who wants victims to pay twice.

The pitch looks legitimate at first. Emails sent to companies that had been hit by groups like DragonForce, Settra, and Anubis claim the sender has spent three years finding holes in the admin panels of ransomware-as-a-service operations. They mention data stolen from the victim that was never made public, which gives the message an unsettling authenticity. But GRIT, which documented the activity in a report published Monday, assesses with moderate confidence that "Ransom Busters" is not a well-meaning third party at all. It is a single affiliate who works across several ransomware operations and has added a second layer of extortion on top of the first.

Two masked hackers working at a terminal in a dark room

"There's no guarantee that payment to any criminal party will result in the deletion of stolen data — there are no magic bullets for remedying data exfiltration," Justin Timothy, a principal consultant at GRIT, said. "This masquerading as beneficent saviors should be treated as a hoax."

Why the Rescue Offer Falls Apart Under Scrutiny

The team at GRIT had a simple question: if Ransom Busters is a benevolent force against cybercrime, why charge a fee that looks like a second ransom? When pressed, the group's explanation only raised more red flags. It claimed that acting without compensation would put its access to the threat actors' infrastructure at risk. That logic doesn't hold, especially since paying the group would have no bearing on its ability to reach criminal servers.

Then there is the legal problem. Breaking into a ransomware group's backend, deleting victim data, and destroying encryption-key backups would violate the U.S. Computer Fraud Abuse Act. A legitimate company would not commit a crime to win business — and certainly would not bill the victim for it.

"When you look at the tools used in the intrusions, the overlaps are striking," Timothy said. "We saw the same reconnaissance software, the same cloud-exfiltration tool, the same backdoor password, and even the same attacker-controlled hostname across two separate incidents."

GRIT's digital forensics team compared two incidents where Ransom Busters contacted victims after the fact. Both intrusions used SoftPerfect Network Scanner for internal reconnaissance, s5cmd to push stolen data to AWS cloud storage, and a remote monitoring tool installed through a PowerShell script. Attackers created a local backdoor account using the same password, "Numlock!123," and both environments pointed back to a single hostname, DESKTOP-BBETH6K.

Operators have plenty of alternative tools for every one of those jobs. Using the identical set in different networks, with the same password and the same host, points to one person running the same playbook. GRIT also noted that the same behavior showed up across several separate ransomware programs, which supports the theory that Ransom Busters is an affiliate with a foot in multiple RaaS operations — someone diverting the victim's payment conversation away from the original gang and toward his own pocket.

A Wavering Line Between Extortion and Ransomware

A masked hacker figure in a dim room facing a glowing terminal

The Ransom Busters persona is part of a broader blurring of roles in the ransomware economy, where the same actors show up on both ends of an attack. GuidePoint posted a second report the same week about UNC6671, an adversary-in-the-middle operation (also tracked as Cordial Spider) that has been running vishing campaigns against financial services, legal, and other industries since April under extortion brands including Falcon, Helix, Pink, Redact, and BlackFile.

That operation collected more than $8 million across 15 Bitcoin wallets, with the average extortion payment around $600,000. GuidePoint found 78 phishing subdomains tied to 76 organizations in 15 industry sectors, and roughly 40 percent of the targets were hedge funds, venture capital firms, private equity shops, or asset managers. The group runs a custom console called Work Panel with role-based access control, target reconnaissance fed by commercial B2B data APIs, and a live queue of phishing calls impersonating Okta and Microsoft 365 logins.

The organizational design is telling. Callers know only their next target's phone number. Managers watch the live session queue but nothing else. Admins control the infrastructure. That separation of duties is a deliberate answer to the insider-risk problem that plagues criminal operations staffed with hired labor, and it lets the group treat callers as interchangeable commodity workers paid per successful capture.

The financial picture behind these schemes keeps shifting too. Check Point's State of Ransomware report for Q2 2026 counted 2,139 organizations listed on data leak sites, with the share held by the top ten groups dropping from 71 percent to 57.6 percent while the number of active groups jumped from 71 to 93. July 2026 alone saw 873 claimed ransomware victims, up from 722 in June and close to the year's high of 909 in March.

What Should Victims Actually Do?

GuidePoint's guidance to companies that receive an unsolicited rescue offer is blunt: treat it as part of the attack. The right move is to route the email to the incident response team, loop in law enforcement, and avoid any payment discussion with a party that inserted itself into the incident.

A few practical points for defenders:

  • Never pay a party that contacts you unsolicited, especially one that claims inside knowledge of your breach. The fact that they know details only proves they were on the attacker's side of the fence.
  • Verify who is on the other end. Legitimate IR firms work through law enforcement referrals, insurers, and legal counsel. They do not cold-email the CEO with a price list.
  • Remember that stolen data is rarely deleted. Researchers have repeatedly found attackers keeping multiple copies of exfiltrated data for resale or re-extortion, and a second payment buys no more certainty than the first one did.
  • Report the approach. Details like the "Numlock!123" backdoor password and the DESKTOP-BBETH6K hostname are exactly the kind of indicators that help researchers link campaigns and warn the next victim.

The bigger lesson is about the ransomware business model itself. Affiliates are increasingly layering extortion tactics one on top of another, and the line between the group that encrypts your files and the one that offers to rescue them has all but disappeared. In that environment, the cheapest protection is a tested backup strategy, patched edge devices, and an incident response plan agreed on before the phone rings.

Organizations that want to stay current on ransomware disclosures and infrastructure warnings can follow the Cybersecurity category archive on this site, which tracks the alerts, exploit chains, and extortion trends behind headlines like this one each day.

The Ransom Busters reveal also fits a wider pattern that security teams have watched all year: attackers abusing legitimate admin tools, cloud storage, and remote management platforms to blend malicious activity with normal operations. Cybercrime infrastructure is becoming industrialized, and the same people who run the encryption phase now see a second income stream in the aftermath. The safest assumption, GRIT says, is that anyone offering to clean up a ransomware mess for cash, out of the blue, is part of the problem.

The episode also underscores how far the original ransomware pitch has drifted from the stereotype of a lone coder holding files hostage. These days the work is split across specialists: someone buys access to a network, someone else plants the RMM tool, a third operator runs the negotiations, and a fourth cleans up the traces. That division of labor is why overlapping details like a reused backdoor password or a familiar hostname matter so much to analysts. They are the fingerprints that tie one "rescue mission" to the same hands that ran the original break-in, and they are exactly what turned a slick sales pitch into a case file.

← Back to Home