Ransom Busters: The Fake Middleman Trying to Divert Ransomware Payments
Ransomware

Illustrative image generated with AI

Ransom Busters: The Fake Middleman Trying to Divert Ransomware Payments

Discover how Ransom Busters, a fake recovery service, contacts ransomware victims before public disclosure to divert payments and steal data.

Text generated by artificial intelligence, published without human review. AI transparency

The attack comes before the data is published

On August 19, 2026, the GuidePoint Security Research and Intelligence Team (GRIT) described a campaign attributed with moderate confidence to a ransomware affiliate operating as a recovery service under the name “Ransom Busters.”

The group contacts targeted organizations before the ransomware operation publicly discloses the incident. Its offer appears straightforward: provide the decryption key and delete the stolen information in exchange for between $20,000 and $60,000.

This behavior differs from that of typical opportunistic brokers, who target victims after an attack has been published on data leak sites. Ransom Busters instead appears to know in advance that an intrusion occurred, who the victim is, and that the attackers obtained the victim’s data.

There are two possible explanations for this knowledge. The group may have compromised the administrative panels used by ransomware-as-a-service (RaaS) organizations, gaining access to decryption keys, victim information, and exfiltrated data. Alternatively, it may be directly involved in the attacks.

The theory: an affiliate collecting twice

According to GRIT, the two investigated incidents show significant technical and operational overlap. The evidence suggests, with moderate confidence, that Ransom Busters is not an independent intermediary but the same affiliate operating across multiple RaaS ecosystems.

The potential criminal scheme is particularly significant. The affiliate takes part in the attack, steals data, and gains access to the ransomware operation’s infrastructure. It then contacts the victim while posing as an external party capable of resolving the crisis.

This allows it to attempt to keep the payment directly rather than split it according to the agreements established by the RaaS organization. The demand would therefore represent a second revenue stream built on the same compromise.

The group claimed it could intervene in cases involving data associated with DragonForce, Settra, and Anubis. The appearance of similar activity across multiple operations strengthens the theory that this is a mobile affiliate, rather than one exclusively tied to a single gang.

Technical indicators link the two cases

GRIT’s analysis identified the same tools in both incidents:

  • SoftPerfect Network Scanner, used to discover systems and devices on the network;
  • s5cmd, a tool for operations on Amazon S3-compatible storage;
  • Remotely, used to monitor and control systems remotely.

Two more specific indicators also appeared in both cases. In each incident, the attackers reportedly created a local account that could be used as a backdoor, with the password Numlock!123. The operators also reportedly used the hostname DESKTOP-BBETH6K.

The presence of the same tools alone does not prove the attacker’s identity: some may be legitimate or readily available. However, the combination of software, local account, password, and hostname provides investigators with a stronger operational lead.

Organizations affected by an incident should search for these elements in endpoint logs, account-management systems, and devices that established remote connections. A single indicator is not enough to attribute an attack, but it can help identify persistence or activity following the initial compromise.

Paying the gang does not necessarily end the crisis

GRIT has not identified any victims that paid Ransom Busters and advises against transferring money to the group. In at least one case, however, the victim paid the RaaS operation believed to be responsible for the attack.

After the payment, the organization’s name and the stolen data did not appear on the gang’s data leak site. Researchers also found no evidence that Ransom Busters published the information outside the RaaS environment.

This outcome does not necessarily mean the data was deleted. A third party may have independent copies and may not honor agreements reached with the ransomware gang. Consequently, paying a criminal operation does not guarantee that every party holding the files will refrain from disclosure.

Coveware confirmed that it handled at least one incident in which the same group, or individual, directly contacted the victim by email and claimed to possess both the decryption key and the stolen data.

The negotiation firm says it has observed similar intermediaries operating under different names since 2024. It considers the more recent activity more serious because the intermediary intervenes before the attack is published, when the victim may not yet have established the full scope of the compromise.

What affected organizations should check

The first step is not to pay Ransom Busters or other unverified parties that simultaneously promise decryption and data deletion. The contact’s identity should be verified through the incident response team, the appointed negotiator, and, where possible, the RaaS operation involved.

Priority technical actions include:

  1. search for Numlock!123 and DESKTOP-BBETH6K in logging systems and forensic data;
  2. investigate the use of SoftPerfect Network Scanner, s5cmd, and Remotely outside normal business processes;
  3. identify and disable local accounts created during or after the intrusion;
  4. immediately rotate potentially exposed passwords, tokens, keys, and credentials;
  5. inspect RaaS administrative panels and other exposed services used to orchestrate the criminal activity;
  6. determine which data was copied and how many parties may have retained a copy.

Emails received from the group should be preserved with full headers, attachments, and metadata. These elements may help link the sender to infrastructure or incidents previously analyzed.

Distrust could fuel new extortion attempts

Coveware believes that growing distrust within RaaS operations could encourage other affiliates to create parallel revenue streams. The traditional model, in which the ransom is divided between the affiliate and the criminal infrastructure operator, creates an incentive to steal information or payments without informing the other participants.

The risk to victims therefore becomes multilayered: they may receive demands from the gang, an affiliate, and parties that later gained access to the data. Each party may claim to control the key or the information, while the victim has no immediate way to verify those claims.

As separate prevention-related context, the Blue Report 2026 states that it assessed defenses through 338 million simulations in production environments. According to its promotional material, when attackers use valid credentials, 37% of actions are blocked. The figure highlights the importance of account controls but does not directly measure the impact of the Ransom Busters campaign.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsransomwareransomware recoveryfake intermediarydata breachcybersecurityransomware payment diversionGRIT researchCoveware
Back to home