A ransomware affiliate calling itself Ransom Busters is targeting victims with a novel extortion scheme, demanding between $20,000 and $60,000 to supposedly delete stolen data from the servers of ransomware gangs, according to a report published by GuidePoint Research and Intelligence Team (GRIT) and shared with The Hacker News. The affiliate proactively emails victim organizations before attacks become public knowledge, claiming to have breached administrative panels maintained by ransomware-as-a-service (RaaS) groups over the past three years. GRIT characterized the activity as "anomalous" because legitimate cybersecurity firms typically only contact ransomware victims after an incident becomes publicly known.

The threat actor has been observed in incidents involving multiple ransomware groups, including DragonForce, Settra, and Anubis. Technical analysis uncovered identical tools across two separate intrusions: SoftPerfect Network Scanner for reconnaissance, s5cmd for data exfiltration to cloud storage via AWS, and the Remotely remote monitoring and management tool installed through PowerShell scripts. Both attacks also featured creation of a local backdoor account using the password "Numlock!123" and detection of the same attacker-controlled hostname, DESKTOP-BBETH6K. In messages to victims, the actor requests contact with CEOs or IT leadership and claims to help companies regain access to their files while deleting all backups held by ransomware groups.

"The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments," said Justin Timothy, a Principal Consultant at GRIT. The report also notes that the possibility of a legitimate organization being behind the activity is "extremely unlikely," as it would violate the U.S. Computer Fraud Abuse Act. According to GRIT, when questioned about charging for assistance, the group offered a "puzzling explanation" that acting without compensation would jeopardize their access to threat actor infrastructure. The striking similarities across incidents suggest a single operator, likely an affiliate rather than a genuine third party, is maintaining this persona.

The technical evidence points to Ransom Busters being a ransomware affiliate exploiting inside access rather than an external benefactor. By maintaining employment across multiple RaaS operations, the actor can identify victim data on servers before extortion becomes public, then pose as a rescuer to extract an additional payment before the official ransomware group makes its own demands. This double-dipping strategy betrays both victims and criminal partners in pursuit of financial gain. The report emphasizes that payment to any criminal party offers no guarantee stolen data will be deleted, dismissing Ransom Busters' claims as a hoax and cautioning there are no "magic bullets" for remedying data exfiltration. Organizations facing ransomware incidents should trust established incident response channels rather than unsolicited offers from supposed insiders, particularly those demanding payment before public disclosure.