September 2, 2026
By esentry Team

Ransomware Affiliate Poses as Recovery Firm to Re-Extort Victims

Threat Overview

A suspected ransomware affiliate is adding a new twist to double extortion by posing as a ransomware recovery firm.

The group, called Ransom Busters, has been contacting organizations shortly after ransomware attacks, sometimes before the incidents become public. It claims to have breached the ransomware operators responsible for the attack, recovered the victim’s stolen data and encryption keys, and can restore encrypted files while deleting the stolen information.

The supposed recovery service comes at a steep price, with demands ranging from $20,000 to $60,000.

However, GuidePoint Security’s Research and Intelligence Team (GRIT) assessed with moderate confidence that Ransom Busters is not an independent recovery provider. Instead, it may be a ransomware affiliate seeking a second payment from victims it was involved in compromising.

The activity has been linked to incidents involving DragonForce, Settra, and Anubis ransomware operations. If confirmed, the tactic represents a particularly deceptive form of double extortion: compromise the victim, then return pretending to be the solution.

Key Points

  • Ransom Busters poses a ransomware recovery company and offers victims decryption keys and deletion of stolen data.
  • Victims are reportedly charged $20,000–$60,000 for the service.
  • The actor contacts victims before their incidents become public, indicating access to information about ongoing ransomware attacks.
  • GRIT identified common tools, infrastructure and techniques across investigated incidents, including SoftPerfect Network Scanner, s5cmd and Remotely.
  • The same local backdoor password and attacker-controlled hostname were identified across two investigated environments, supporting the assessment of a common affiliate.  
  • The activity appears designed to divert ransom payments away from the ransomware operators while generating additional profit for the affiliate.
  • Researchers have not identified evidence that victims paid Ransom Busters at the time of reporting.  

Why It Matters

The operation highlights an emerging problem in the Ransomware-as-a-Service (RaaS) ecosystem where affiliates may exploit their access to victims for their own benefit, even at the expense of the ransomware group they work with.

For victims, the distinction is critical. An unsolicited party claiming to possess decryption keys or stolen data is not automatically a legitimate recovery provider. Paying the actor also provides no reliable assurance that stolen information has been deleted or that other criminals do not possess copies.

More importantly, communications from such actors can contain valuable intelligence. Their knowledge of a non-public incident, stolen datasets, infrastructure or ransomware operation may help responders establish how the intrusion occurred and identify other parties with access to the environment.

Recommendations

Organizations contacted by suspected recovery actors should:

  • Preserve the original email, headers, attachments and all communications as evidence.
  • Do not provide additional information about the incident or internal environment.
  • Validate any claimed decryption keys or stolen data through the incident-response team.
  • Correlate the actor's claims with forensic evidence from the ransomware intrusion.
  • Investigate shared tools, accounts, infrastructure and persistence mechanisms for links to other attacks.
  • Involve appropriate legal, incident-response and law-enforcement teams before engaging with the actor.