LIVE NEWS
  • Meta’s New AI Agent Wants to Get Personal With You
  • How To Change And Customize Your Apple CarPlay Display
  • Hedge funder Brian Kelly built Bracket22 to be powered entirely by AI
  • Ukraine contracting around 1,000 Patriot missiles from allies, defense chief says
  • The New Race for Cross-Chain Liquidity: Why the Future of DeFi May Depend on Moving Capital Seamlessly
  • Threat actors are giving AI agents a bigger role in cyberattacks
  • NuScale Power Stock Broke Out in August. Is It a Buy?
  • Where on Earth is safest from global catastrophe?
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Rogue ransomware affiliate poses as data recovery firm to steal payments
Cybersecurity

Rogue ransomware affiliate poses as data recovery firm to steal payments

primereportsBy primereportsAugust 19, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Ransomware

A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting victims before the attacks become public and claiming it can provide decryption keys and delete stolen data for a fee.

GuidePoint Security’s Research and Intelligence Team (GRIT) disclosed this activity after responding to several recent ransomware attacks in which victims received emails from Ransom Busters offering to help recover from the attack.

The messages were suspicious because they were sent to victims before the attacks became public, raising questions about how they knew about the cyberattacks in the first place.

image

Ransom Busters claimed it exploited vulnerabilities in administrative panels used by ransomware-as-a-service (RaaS) operations, giving it access to encryption keys and data stolen from victims.

The group offered to delete the stolen data from ransomware servers, including those belonging to DragonForce, Settra, and Anubis, for between $20,000 and $60,000.

However, evidence from two incidents leads GRIT to believe Ransom Busters is likely not a true recovery firm, but the ransomware affiliate responsible for the attacks.

In both cases, the attackers used the same software, including SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool. They also utilized the same tactics, including creating a local backdoor account using the password ‘Numlock!123’ and the same attacker-controlled hostname, ‘DESKTOP-BBETH6K’.

GRIT says it observed overlapping activity across multiple RaaS operations and believes, with moderate confidence, that Ransom Busters is a single ransomware affiliate using its access to steal ransom payments from the ransomware gangs it works with.

GRIT told BleepingComputer that it has not seen any victims pay Ransom Busters and discourages victims from doing so. However, in one incident involving Ransom Busters, the victim instead paid the RaaS operation behind the attack.

The researchers say the victim’s name and stolen data were not published on the ransomware operation’s data leak site, and they found no evidence that Ransom Busters leaked the stolen data outside the RaaS environment.

Ransomware negotiation firm Coveware confirmed to BleepingComputer that they too recently responded to at least one incident where the same group or individual contacted a victim.

“This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data,” Elizabeth Cookson, Senior Director of IR at Coveware, told BleepingComputer.

Coveware says it has encountered similar “middlemen” using other names as far back as 2024, but says this activity is distinct from the typical “ambulance chasers” who contact victims only after their attacks have been publicly disclosed.

“This type of interference on a non-public incident is much more concerning,” Lizzie told BleepingComputer.

Coveware says interference from a rogue party with access to stolen data increases risk for victims, as paying the ransomware operation may no longer ensure that everyone with access to the data will honor an agreement not to leak it.

The company believes increased distrust within Ransomware-as-a-Service operations could lead to more of this behavior, as affiliates attempt to generate additional profits outside of normal revenue-sharing arrangements with ransomware operators.

BleepingComputer has also previously warned that third-party ransomware recovery services create forum accounts and privately contact victims who publicly disclose ransomware infections, claiming they can decrypt affected files.

However, those services generally approached publicly known victims, while Ransom Busters’ knowledge of non-public incidents is far more concerning.


article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleA SpaceX rocket slammed into the moon this month — and a NASA spacecraft has spotted its lunar grave
Next Article Down 50% on crypto and burning $8 million in cash, this Nasdaq firm just pivoted to event robots to survive
primereports
  • Website

Related Posts

Cybersecurity

Threat actors are giving AI agents a bigger role in cyberattacks

September 8, 2026
Cybersecurity

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

September 7, 2026
Cybersecurity

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

September 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 2026116 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202673 Views

An $18bn settlement – and Zuckerberg barely blinked. The tech titans must be stripped of their power, and soon | Jonathan Freedland

August 28, 202626 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Crypto
  • Cybersecurity
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Meta’s New AI Agent Wants to Get Personal With You
  • How To Change And Customize Your Apple CarPlay Display
  • Hedge funder Brian Kelly built Bracket22 to be powered entirely by AI
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.