The pitch arrives by email, after the worst has already happened.
A group calling itself Ransom Busters tells the victim it has spent 3 years breaking into ransomware operators' infrastructure, that it has found their stolen files sitting on those servers, and that for a fee it will restore access and delete every copy the gang holds. The asking price runs from $20,000 to $60,000.
GuidePoint Security's incident response team has now worked two of these cases. What they found in both does not support the story.
The same fingerprints in both intrusions
GuidePoint's DFIR responders compared the two environments and found overlaps that are hard to explain if Ransom Busters is a third party who arrived after the fact:
- The same tools for internal reconnaissance, data theft and remote access — SoftPerfect Network Scanner, s5cmd, and commercial RMM software
- Local backdoor accounts sharing a password, reported as Numlock!123
- The same attacker-controlled hostname, DESKTOP-BBETH6K, in both victim networks
A recovery service that had hacked the criminals would arrive with the criminals' data. It would not arrive having left its own reconnaissance tooling and reused backdoor accounts inside the victim.
What GuidePoint actually concludes
GRIT, GuidePoint's research and intelligence team, assesses with moderate confidence that Ransom Busters is not an outside researcher at all but a single ransomware affiliate, working with several ransomware-as-a-service operations and running the same playbook in each victim.
That matters, and so does the confidence level. Moderate confidence is not proof, and we are not going to upgrade it here. What the evidence establishes is that the same operator was present in both intrusions. Who they are and how many crews they work with is inference from tradecraft.
Justin Timothy, a principal consultant at GRIT, puts the alternative plainly: either the operators were hiding where their access really came from, or they were not working inside the law.
The three groups it turned up alongside
GuidePoint saw the Ransom Busters approach in incidents involving DragonForce, Settra and Anubis.
That spread is the part worth sitting with. An affiliate is not the brand. Affiliates rent the encryptor and the leak site, take a cut, and are free to work with more than one operation at a time — which is precisely how the same toolkit, the same password and the same hostname end up in victims attributed to three different names. We wrote about DeadLock running its leak site off Polygon and Storm standing up a new leak site with 19 victims in 8 days; the branding churns far faster than the people behind it.
Why the scam works
Because it is aimed at the one moment when judgement is worst.
A company mid-incident has already lost its files, already knows the data is gone, and is already being told by its lawyers that paying the gang is a decision with consequences. Into that arrives an offer that is not a ransom — it is a recovery service. It lets everyone involved describe the payment as something other than paying criminals.
There is a second, colder read. Even if a buyer somehow believed the whole story, the thing being sold is a promise of deletion, which is unverifiable by construction. That is the same defect in paying the original gang. You cannot audit a deletion you did not witness on infrastructure you do not control.
What to do
- Route every extortion contact to one place. Ransom Busters emails staff directly. Whether an employee forwards it, replies, or panics is decided long before the email arrives, by whether anyone told them what to do.
- Treat a second party claiming to hold your data as evidence, not as an offer. The email itself is intelligence: it tells you someone still has access or still has the files. Give it to your responders.
- Hunt for the artefacts. A named hostname and a reused backdoor password are the cheapest possible detections. Query for DESKTOP-BBETH6K and for local accounts created during the incident window, and check for s5cmd and SoftPerfect Network Scanner in places nobody deployed them.
- Watch RMM as an intrusion tool. It was in both incidents, and it looks like administration until you check who installed it — the same pattern as Interlock turning an IR tool into an intrusion tool.
- Decide the payment question before you need it. Not because paying is always wrong, but because a decision made in hour three of an outage is not a decision.
What is not established
- Who Ransom Busters is. GRIT's single-affiliate assessment is moderate confidence, from tradecraft overlap.
- Whether anyone paid. No payments have been reported either way.
- Whether the claim is entirely false. The evidence shows the same operator inside both victims. It does not separately disprove that this operator also has access to other groups' servers — it just makes the heroic version unnecessary as an explanation.
- Any law enforcement position. None has been reported.