// 1 CRITICAL · 3 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
A ransomware affiliate operates as a fake recovery firm, contacting victims before attacks are published. GuidePoint Security GRIT documents forensic overlap that erodes trust in the RaaS model.

A ransomware affiliate built a parallel identity as a recovery firm, contacting victims of attacks not yet public to offer decryption and data deletion at market rates. On August 18, 2026, GuidePoint Security GRIT research documents how this scheme erodes the trust mechanism underpinning the entire RaaS market: if stolen data remains in multiple hands, the promise of deletion becomes worthless.

Key Takeaways
  • Ransom Busters contacts victims before attack publication, offering decryption and data deletion for $20,000–$60,000 according to BleepingComputer.
  • GRIT responded to two incidents with overlapping forensic evidence: same tools (SoftPerfect Network Scanner, s5cmd, Remotely RMM), same backdoor password "Numlock!123", same attacker-controlled hostname "DESKTOP-BBETH6K".
  • GRIT assesses with "moderate confidence" that Ransom Busters is the same affiliate behind the attacks, not a legitimate recovery firm.
  • Coveware confirmed at least a third incident with an identical pattern, extending confirmation beyond the two direct response cases.

The Internal Double-Extortion Mechanism

Ransom Busters operates in a critical time window: contact occurs between compromise and attack publication, when the victim is under pressure but the secondary data market has not yet activated. According to the source, the entity offers a package priced at $20,000–$60,000 that includes decryption and deletion of stolen data.

The distinction from a legitimate recovery firm is structural. Justin Timothy, principal threat intelligence consultant at GuidePoint Security, observes via Dark Reading that legitimate firms do not provide pricing before a scoping call, while Ransom Busters introduces the financial ask in initial communications, replicating ransomware actor behavior. The demand for Bitcoin payment is a further indicator Timothy considers decisive: no credible industry vendor uses this method.

The entity claims to have compromised RaaS operation admin panels, acquiring "almost all their infrastructure." This claim has not been independently verified. The source does not establish whether this is genuine access or a cover story.

The Forensic Chain Linking the Two Roles

The technical convergence between the RaaS attacks and Ransom Busters contacts is documented through multiple layers of overlap. In two separate forensic response incidents, GRIT isolated identical artifacts: the SoftPerfect Network Scanner tool for network reconnaissance, s5cmd for S3 data transfer, Remotely RMM for persistent remote access. The local backdoor password is identical: "Numlock!123". The attacker-controlled hostname is the same: "DESKTOP-BBETH6K".

This multiplicity of contact points exceeds the threshold of random coincidence but does not reach absolute certainty. GRIT explicitly states the confidence level as "moderate," leaving open the formalization of additional elements for elevation to "high." The source does not specify which elements are missing for this leap.

Ransom Busters confirmed access to the identical dataset held by the affiliate when questioned, according to Dark Reading. This access to pre-publication data is the discriminator that separates the phenomenon from legitimate recovery firms, which operate exclusively post-disclosure.

The Breach of the Criminal Social Contract

"If both the RaaS operation and Ransom Busters retain copies of the stolen data, victims have no reasonable guarantee that all copies will be destroyed." — Justin Timothy, GuidePoint Security (via Dark Reading)

The RaaS model rests on a repeated commitment mechanism: the affiliate promises to delete data in exchange for payment, and the RaaS brand's reputation depends on the credibility of that promise. If the affiliate monetizes the same victim in parallel while retaining a private copy of the data, the payment for suppression loses its contractual value.

Elizabeth Cookson, Senior Director of IR at Coveware, confirms via BleepingComputer at least one other incident with mid-incident contact by a third party claiming access to both the decryption key and stolen data. Cookson distinguishes this pattern from the longer history of similar "middlemen" observed since 2024: the pre-publication activity is "far more concerning" than post-disclosure contacts, because it breaks the expected timeline and suggests internal access to the attack chain.

What to Do Now

For organizations managing ransomware incidents, the source suggests specific verification points:

  • Verify contact timing: legitimate recovery firms operate after attack publication, not before.
  • Scrutinize upfront pricing demands, which replicate ransomware actor communication patterns.
  • Treat any request for Bitcoin payment as an indicator of malicious intent.
  • Confirm the origin of any offered decryption key through independent channels, without assuming that access to implied data derives from compromise of the RaaS panel.

The dossier does not document specific remedial measures for affected RaaS operations. It does not emerge whether DragonForce, Settra, or Anubis have responded to the events.

The Line Between Affiliate and Competitor

The Ransom Busters case outlines a mutation of the ransomware market that traditional defenses do not cover: the risk is no longer only external, but intra-criminal. When an affiliate becomes a competitor to its own RaaS operator, the victim's security perimeter fragments. Negotiation with the official channel no longer guarantees data confidentiality, because a parallel copy could persist in hands not bound by the RaaS contract.

The scale of the phenomenon remains to be quantified: three confirmed cases, two with direct response and one with Coveware confirmation, do not establish whether this is an expanding pattern or an isolated case. The total number of victims contacted is unknown. GRIT has not observed payments made to Ransom Busters, and in one case the victim paid the original RaaS operation without data being published or leaked by third parties.

The limit of the dossier is also its sharpest warning: trust, even criminal trust, is a consumable resource.

Frequently Asked Questions

Has Ransom Busters actually received payments?

According to GRIT, no payments to Ransom Busters have been observed. In one documented case, the victim paid the original RaaS operation.

How many RaaS operations were involved?

GRIT research observed the behavior in incidents linked to DragonForce, Settra, and Anubis, according to the direct citation from the blog post. It does not emerge whether the pattern extends to other operations.

Is it certain that Ransom Busters is the affiliate behind the attacks?

GRIT expresses "moderate confidence," based on multiple forensic overlaps. The source does not establish whether this is an official affiliate, former affiliate, or entity with independent access.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. darkreading.com
  3. wiz.io