Actor Profile

Ransom Busters is a suspected ransomware affiliate operating across multiple Ransomware-as-a-Service (RaaS) platforms, including DragonForce, Settra, and Anubis. Rather than a legitimate recovery service, GuidePoint Security's GRIT assesses with moderate confidence that this entity is a rogue affiliate exploiting its insider access to conduct double-extortion fraud. The actor contacts ransomware victims before attacks become public, falsely claiming to have exploited vulnerabilities in RaaS administrative panels to obtain decryption keys and stolen data. The true motivation appears to be stealing ransom payments directly from victims while bypassing revenue-sharing agreements with the RaaS operators they work for. This represents an emerging threat model where affiliates monetize their access outside normal ransomware business structures, increasing victim risk by introducing additional parties with access to exfiltrated data.

TTPs (Tactics, Techniques, Procedures)

The actor demonstrates consistent tradecraft across multiple incidents. Initial access methods are not detailed, but post-compromise activity includes: deployment of SoftPerfect Network Scanner for network reconnaissance, use of s5cmd (likely for data exfiltration to cloud storage), and installation of the Remotely remote monitoring and management (RMM) tool for persistent access. Persistence is established via creation of local backdoor accounts using the password 'Numlock!123'. Infrastructure reuse is evident through consistent use of the attacker-controlled hostname 'DESKTOP-BBETH6K' across incidents. The fraud operation itself involves contacting victims via email before public disclosure, impersonating a recovery service, and demanding payments between $20,000-$60,000 for decryption keys and data deletion. GRIT observed overlapping activity across multiple RaaS operations, suggesting the affiliate maintains access to multiple ransomware ecosystems simultaneously.

Targets & Patterns

Specific targeted sectors and geographic focus are not disclosed in available reporting. Victims appear to be organizations already compromised by ransomware operations including DragonForce, Settra, and Anubis RaaS platforms. The targeting pattern suggests opportunistic selection based on the affiliate's existing access through legitimate ransomware operations rather than independent victim selection. The actor's ability to contact victims before attacks become public indicates they are targeting organizations during the window between initial compromise/data exfiltration and public disclosure on data leak sites. Coveware notes this represents a shift from typical "ambulance chaser" recovery scams that only contact publicly disclosed victims, making this activity significantly more concerning due to the insider knowledge required.

Historical Context

Coveware reports encountering similar "middlemen" using other names dating back to 2024, though the specific Ransom Busters persona appears to be a more recent development first disclosed by GuidePoint GRIT in August 2026. This activity represents an evolution from traditional third-party recovery scams that contact publicly known ransomware victims. The emergence of rogue affiliates attempting to monetize access outside normal RaaS revenue-sharing arrangements reflects growing distrust within the ransomware ecosystem. Coveware assesses this trend may increase as affiliates seek additional profit channels. The activity is distinct from previously documented recovery scams because it requires insider access to non-public incident information, suggesting the actor is embedded within active ransomware operations rather than operating as an external opportunist.

Defensive Recommendations

  • Monitor for creation of local accounts with suspicious passwords, particularly those matching known affiliate patterns (e.g., 'Numlock!123'); alert on new local administrator account creation outside change management windows
  • Detect deployment of legitimate remote monitoring tools (RMM) such as Remotely, AnyDesk, or similar software in environments where they are not authorized; implement application allowlisting to prevent unauthorized RMM installation
  • Identify use of SoftPerfect Network Scanner and s5cmd through process execution monitoring (Sysmon Event ID 1) and network connection logs; these tools are frequently abused for reconnaissance and cloud exfiltration
  • Investigate suspicious hostnames that do not match organizational naming conventions, particularly generic patterns like 'DESKTOP-[random string]'; maintain asset inventory to identify unauthorized systems
  • If contacted by third-party recovery services before an incident becomes public, treat this as a critical indicator that the attacker may be a rogue insider; engage trusted incident response firms and avoid payment to unverified parties claiming insider access to ransomware infrastructure