Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Circle still tells users to buy Noble USDC on Coinbase after cutoff date passes

    August 18, 2026

    NASA Glenn’s Legacy Forged Through Decades of Flight Research

    August 18, 2026

    Indigenous food sovereignty is one of the most overlooked conservation strategies (commentary)

    August 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Circle still tells users to buy Noble USDC on Coinbase after cutoff date passes
    • NASA Glenn’s Legacy Forged Through Decades of Flight Research
    • Indigenous food sovereignty is one of the most overlooked conservation strategies (commentary)
    • Chevron hits pay in Sub-Saharan Africa with oil & gas condensate discovery offshore Angola
    • Vance Pitches New Objective for Iran War: Lower U.S. Gas Prices
    • The Cancer Act 1939 doesn’t make it ‘illegal to cure cancer’ – Full Fact
    • In Ceuta, migrants stranded at Europe’s gates await their fate
    • Gehen der Ukraine die Schutzschilde aus? Mit Nico Lange – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ‘Ransom Busters’: Ransomware Actor Poses as Recovery Service

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 18, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model.

    According to the GuidePoint Research and Intelligence Team (GRIT), a malicious entity referring to itself as “Ransom Busters” has sent an email to cyberattack victims, claiming to have infiltrated the servers of multiple criminal groups and discovering data belonging to the victim. For a fee, the email claims, Ransom Busters “can return your files to you and destroy all backups held by the group.” The email claims the attackers have also gained access to encryption keys that can be used to help victims access their files.

    “We observed this behavior while responding to incidents from threat groups including DragonForce, Settra, and Anubis,” according to the blog post, released today. “The threat actor claimed this access allowed them control over ‘almost all of their infrastructure. Like [ransomware as a service [RaaS] groups, Ransom Busters’ motivation appears to be financial. Ransom Busters confirmed access to the exact same dataset that the ransomware affiliate possessed, when questioned. The group offered to delete the victim’s stolen data from the ransomware groups’ servers for a fee of between $20,000 to $60,000.”

    Related:Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor’s Office

    Ransom Busters’ Red Flags

    There are multiple red flags behind the purported offer of help, as Justin Timothy, principal threat intelligence consultant at GuidePoint Security, explained in the blog post. For one, in the cases GRIT observed, Ransom Busters reached out before the ransomware attack became public knowledge; incident-response firms usually offer their services after an attack is disclosed.

    Ransom Busters also claims in its communications to have accessed the administrative panel of ransomware-as-a-service (RaaS) actors. Offensive actions from a third party, Timothy noted, could be considered a violation of the US government’s Computer Fraud Abuse Act.

    “We would not expect a legitimate organization to potentially commit a crime, much less to charge a fee in exchange for doing so,” Timothy wrote.

    GuidePoint’s Digital Forensics and Incident Response (DFIR) team responded to two incidents where Ransom Busters contacted victims, and in both cases, the intrusions were notably similar (as Timothy wrote, while many intrusions share similar elements, “each attack typically has its own unique characteristics in terms of tooling used and persistence mechanisms within the victim’s network”). There were overlaps in the tools used for internal reconnaissance, data exfiltration, and remote monitoring and management (RMM). The local backdoor accounts also shared a password, and the same attacker-controlled hostname was identified across attacks.

    Related:Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

    GRIT ultimately assessed with moderate confidence that Ransom Busters is not a true third-party researcher, but rather a single ransomware affiliate that works with multiple RaaS actors and implements the same tactics across victim environments. The ultimate goal of this, GRIT believes, is that Ransom Busters is “using their affiliate access to divert ransom payment discussions away from the original ransomware operation.”

    In many RaaS operations, affiliates do not have unilateral control over every copy of stolen data or the broader extortion infrastructure. As a result, victims have little ability to verify claims that data has actually been deleted or that all parties with access to the information have relinquished it.

    GRIT believes the activity may represent an attempt by an affiliate to monetize victims outside the traditional RaaS payment structure, potentially diverting revenue away from the ransomware operation itself.

    Don’t Get Busted by the Busters

    Timothy tells Dark Reading that Ransom Busters’ tactics actually undermine the core RaaS business model.

    Related:Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

    “A standard part of ransom negotiations involves the threat actor’s commitment to delete exfiltrated data upon payment. If both the RaaS operation and Ransom Busters retain copies of the stolen data, victims have no reasonable assurance that all copies will be destroyed,” he says. “That alone can make any payment for data suppression effectively worthless. From a financial standpoint, Ransom Busters’ activity directly damages the credibility and revenue potential of the RaaS operations they are affiliated with.”

    Although he is not aware of a case where these tactics have succeeded, Timothy stresses that a contact made from a non-law enforcement entity mid-incident is very unusual. Legitimate outreach typically comes from a corporate email domain and not a free or privacy-focused service like ProtonMail (Ransom Busters used a privacy-focused email address with no verifiable domain, he adds).

    “Legitimate IR firms also do not provide pricing before an initial scoping call. They need to understand the incident before quoting anything. Ransom Busters, by contrast, introduced a financial demand early in communications, closely mirroring the behavior of actual ransomware actors,” Timothy says. “Finally, no credible cybersecurity vendor requests payment in Bitcoin. That alone should be treated as a strong indicator of malicious intent.”

    actor Busters poses ransom ransomware recovery Service
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

    Strategy says MSTR price recovery hinges on fixing STRC

    Did Secret Service agent share private details about how Trump acts in presidential limousine?

    AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files

    Microsoft confirms outage affecting search in Microsoft 365 apps

    Microsoft tests faster Windows File Explorer, new context menu

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Circle still tells users to buy Noble USDC on Coinbase after cutoff date passes

    August 18, 2026

    NASA Glenn’s Legacy Forged Through Decades of Flight Research

    August 18, 2026

    Indigenous food sovereignty is one of the most overlooked conservation strategies (commentary)

    August 18, 2026

    Chevron hits pay in Sub-Saharan Africa with oil & gas condensate discovery offshore Angola

    August 18, 2026
    Latest Posts

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Circle still tells users to buy Noble USDC on Coinbase after cutoff date passes

    August 18, 2026

    NASA Glenn’s Legacy Forged Through Decades of Flight Research

    August 18, 2026

    Indigenous food sovereignty is one of the most overlooked conservation strategies (commentary)

    August 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.