Ransom Busters: The Ransomware Scam That May Be Coming for Victims Before the Attack Is Even Public + Video

Listen to this Post

Featured ImageIntroduction: When the “Rescue Team” May Be Part of the Attack

Imagine waking up to discover that your company has been hit by ransomware. Files are encrypted, sensitive information may have been stolen, employees cannot work, and every minute feels expensive.

Then, before the ransomware gang has even publicly announced the attack, an unfamiliar company contacts you.

It calls itself “Ransom Busters.”

The message sounds almost reassuring. It claims to have access to your decryption keys. It says it can remove your stolen information from the attackers’ infrastructure. All it wants is a payment—potentially tens of thousands of dollars—to make the crisis disappear.

At first glance, this might look like an emergency recovery service.

But cybersecurity researchers believe the reality could be considerably darker.

According to research from GuidePoint

That possibility changes the entire story.

This is no longer simply about ransomware criminals attacking organizations. It is about criminals potentially creating a second revenue stream by impersonating rescuers, approaching victims privately, and attempting to extract additional payments before the original ransomware incident becomes public.

The Suspicious Message Arrives Before the News

The most important detail in the investigation is timing.

GRIT encountered several incidents in which victims received communications from Ransom Busters before their ransomware attacks had become publicly known.

That immediately raised an uncomfortable question: How did Ransom Busters know the victim had been compromised?

Traditional recovery scammers and so-called ransomware “ambulance chasers” generally learn about an incident after it becomes public. They monitor leak sites, security discussions, disclosure announcements, or other public sources before approaching victims with offers of assistance.

Ransom Busters appeared to operate differently.

If an organization has not announced an attack, its name has not appeared on a ransomware leak site, and the attacker has not publicly disclosed the incident, an outside recovery company should have no obvious reason to know about it.

That makes advance knowledge potentially significant evidence of an insider connection.

The Recovery Story Ransom Busters Told Victims

Ransom Busters reportedly claimed that it had compromised administrative panels associated with ransomware-as-a-service operations.

According to the claims, those intrusions supposedly gave the group access to both decryption keys and stolen victim data.

The organization allegedly offered to use that access to help victims recover their files and remove stolen information from ransomware infrastructure.

The price was substantial.

The reported demands ranged from approximately $20,000 to $60,000, depending on the incident.

Ransom Busters reportedly claimed that it could remove data from infrastructure associated with ransomware operations including DragonForce, Settra, and Anubis.

On paper, such a service might sound attractive to a desperate victim.

In practice, paying an unknown criminal intermediary creates an entirely different set of risks.

GRIT Finds the Same Tools Behind Multiple Incidents

The investigation became more concerning when GRIT identified technical similarities between incidents involving Ransom Busters.

Researchers observed the same or highly similar software being used during multiple compromises.

Among the tools identified were SoftPerfect Network Scanner, s5cmd, and Remotely.

Individually, none of these tools proves attribution.

Legitimate administrators and security professionals can use network scanners, cloud-storage utilities, and remote-management software.

The significance comes from the combination.

When the same tools appear alongside the same operational behaviors across multiple incidents, investigators can begin connecting activity that initially appears unrelated.

The “Numlock!123” Backdoor Clue

One of the more striking overlaps involved the creation of a local backdoor account using the password:

Numlock!123

GRIT reportedly observed this same credential pattern in the investigated incidents.

Researchers also identified the same attacker-controlled hostname:

DESKTOP-BBETH6K

Again, no individual indicator should be treated as absolute proof of attribution.

But cybersecurity investigations rarely depend on a single clue.

When infrastructure, tools, account-creation behavior, passwords, hostnames, and attack techniques repeatedly overlap, the probability of a common operator increases.

Why the Hostname Matters

A hostname such as DESKTOP-BBETH6K might look insignificant to someone investigating a ransomware incident.

To an incident responder, however, repeated infrastructure artifacts can become extremely valuable.

Attackers often attempt to blend into legitimate environments, but operational habits can follow them from one intrusion to another.

They may reuse scripts.

They may reuse credentials.

They may deploy the same tools.

They may follow familiar procedures.

And sometimes they forget to change seemingly meaningless details.

That is why incident response teams collect and correlate endpoint telemetry, authentication logs, process execution records, network connections, cloud activity, and persistence mechanisms.

A tiny repeated artifact can eventually become part of a much larger attribution picture.

The Bigger Theory: A Ransomware Middleman With a Second Business Model

GRIT believes, with moderate confidence, that Ransom Busters may represent a single ransomware affiliate operating across multiple ransomware-as-a-service ecosystems.

If that assessment is correct, the financial motivation becomes easier to understand.

RaaS affiliates typically work with ransomware operators under revenue-sharing arrangements.

The affiliate gains initial access to a victim, moves through the environment, steals information, encrypts systems, and negotiates a ransom.

The ransomware operator may receive a portion of the final payment.

But what happens if the affiliate can make money without waiting for the normal ransomware negotiation?

That is where the alleged Ransom Busters model becomes particularly interesting.

An affiliate could potentially compromise a victim, obtain access to the stolen data and encryption infrastructure, and then approach the victim independently.

Instead of simply participating in the official ransom demand, the affiliate—or someone with access to the operation—could attempt to extract an additional payment.

That would effectively turn one victim into two potential revenue opportunities.

The Most Dangerous Part Is Not the $60,000 Demand

The monetary demand is alarming, but it may not be the greatest danger.

The deeper problem is trust.

A victim negotiating with a ransomware organization is already operating under extreme uncertainty.

If another party appears and claims to possess the decryption key and stolen data, the victim has to determine:

Who actually controls the key?

Who controls the stolen files?

Who can delete the information?

Who can publish it?

Who can access the

And, perhaps most importantly, who is telling the truth?

If multiple criminals have access to the same stolen data, paying one of them may not guarantee that the information will remain private.

Coveware Reports Seeing Similar Activity

Ransomware negotiation firm Coveware also reportedly encountered an incident involving the same group or individual.

According to Coveware, the third party contacted a victim directly and claimed to possess both the decryption key and the stolen data.

Coveware said it has encountered other ransomware middlemen using different identities as far back as 2024.

However, researchers distinguish this activity from the more familiar ransomware recovery scammers who contact victims after an attack has already become public.

The timing is the crucial difference.

Why Non-Public Interference Is So Concerning

There is a major distinction between knowing that a company has suffered ransomware because the company announced it and knowing about the intrusion while it is still confidential.

The first can be explained by public monitoring.

The second suggests access to information that should not yet be available.

That creates a troubling possibility: the intermediary may have direct visibility into the criminal operation, the victim’s stolen data, or the attack itself.

For defenders, this means that an unsolicited recovery email arriving immediately after a suspected compromise should not automatically be interpreted as help.

It may instead be another phase of the attack.

Paying One Criminal Does Not Necessarily Stop Another

Ransomware negotiations traditionally involve an uncomfortable promise: pay the attackers and they claim they will decrypt the systems and refrain from publishing stolen information.

That promise was never guaranteed.

But the alleged emergence of rogue intermediaries makes the situation even more complicated.

If an affiliate, ransomware operator, access broker, or another criminal has independently retained copies of the stolen information, the victim may have no practical way to verify that every person with access has deleted it.

The traditional ransom agreement therefore becomes much less meaningful.

A victim could potentially pay the ransomware operator and still face another criminal demanding money.

The Ransomware-as-a-Service Ecosystem Creates the Perfect Environment

Ransomware-as-a-service has transformed cybercrime into something resembling a distributed business ecosystem.

Different participants may specialize in different stages:

Initial access brokers obtain credentials.

Affiliates compromise organizations.

Operators maintain ransomware infrastructure.

Developers create encryption malware.

Negotiators communicate with victims.

Data brokers trade stolen information.

Money launderers move cryptocurrency.

The more fragmented the ecosystem becomes, the more opportunities exist for disputes, theft, betrayal, and competing monetization strategies.

Ransom Busters could represent an extreme example of that fragmentation if GRIT’s assessment proves correct.

A Criminal Ecosystem Can Turn Against Itself

There is an important economic principle behind this development.

Cybercriminals may cooperate when cooperation increases profit.

But cooperation does not eliminate competition.

If one participant realizes that it can earn more by secretly monetizing access to a victim, the incentives change.

An affiliate could potentially steal from its ransomware partner.

A criminal could sell the same access to multiple buyers.

A rogue participant could retain stolen data.

Or someone inside the ecosystem could impersonate a recovery provider.

The result is an environment where criminals cannot necessarily trust one another.

Ironically, the same distrust they create for their victims can eventually infect their own underground economy.

Deep Analysis: What Defenders Should Look for

Identify Suspicious Local Accounts

Incident responders should immediately review recently created local accounts, especially accounts that appear shortly before suspicious activity.

On Windows systems, defenders can inspect local users with:

Get-LocalUser | Select-Object Name, Enabled, LastLogon

Security teams should investigate unfamiliar accounts rather than simply deleting them.

Deleting evidence too early can destroy valuable forensic information.

Review Recent Account Creation Events

Windows Security logs can help identify account creation activity.

A basic PowerShell search can include:

Get-WinEvent -FilterHashtable @{
LogName='Security'
Id=4720
} | Select-Object TimeCreated, Message

Event ID 4720 is associated with the creation of a user account.

Organizations should correlate these events with authentication logs, endpoint telemetry, and known attack timelines.

Investigate Remote Access Software

Remote-management tools can be legitimate, but attackers increasingly abuse legitimate software because it allows them to operate without deploying obviously malicious binaries.

Defenders can search endpoint telemetry for unexpected remote-access applications and investigate:

Get-Process | Where-Object {
$_.ProcessName -match 'remotely|remote|rmm'
}

The command is only a starting point; process names alone are not proof of malicious activity.

Search for Known Hostnames

Incident responders should search historical logs for recurring attacker infrastructure.

For example:

Get-WinEvent -LogName Security |

Select-String -Pattern DESKTOP-BBETH6K

In an enterprise environment, centralized SIEM searches are preferable because the hostname may appear in authentication, endpoint, DNS, DHCP, and network telemetry.

Review Network Discovery Activity

Network scanners can generate useful forensic evidence.

Defenders should investigate unusual internal reconnaissance, particularly from workstations or servers that normally have no reason to perform broad network discovery.

Look for:

Unexpected SMB enumeration

Unexpected RDP enumeration

Large numbers of connection attempts

Scanning from ordinary employee endpoints

Scanning shortly after credential compromise

The objective is not to block every scanner.

The objective is to identify scanning that does not fit the system’s normal role.

Investigate Cloud Storage Utilities

Tools such as s5cmd can have legitimate administrative uses, but their presence during a ransomware intrusion deserves attention.

Security teams should examine:

Process execution

Command-line arguments

Cloud authentication events

Object-storage access

Large file transfers

New access keys

Unusual API calls

Data compression before transfer

The combination of cloud-storage access and suspicious endpoint activity can indicate attempted data exfiltration.

Search for Credential Abuse

The most dangerous moment may occur after attackers obtain legitimate credentials.

Defenders should therefore monitor for:

Impossible-travel authentication

New administrative sessions

Authentication from unusual hosts

Unexpected privilege escalation

New MFA registrations

Password resets

New service accounts

Suspicious remote logons

A successful login does not mean the activity is legitimate.

Modern attackers increasingly operate through valid credentials precisely because those sessions can appear normal to conventional security controls.

Preserve Evidence Before Remediation

One of the most common incident-response mistakes is immediately wiping compromised systems.

Containment is important, but evidence is equally important.

Before destroying compromised infrastructure, responders should preserve relevant logs, memory where appropriate, disk images, authentication records, endpoint telemetry, and cloud audit information according to their incident-response procedures.

The objective is to understand:

How did they get in?

What did they access?

What did they steal?

Who else may have access?

Did they create persistence?

Did they communicate with another criminal infrastructure?

Treat Unexpected “Recovery” Offers as an IOC

An unsolicited recovery offer should itself become part of the investigation.

Record:

Sender address

Reply-to address

Email headers

Sending infrastructure

URLs

Attachments

Cryptocurrency addresses

Claimed ransom amount

Claimed ransomware family

Time of contact

Information known by the sender

Do not simply delete the email.

The message may contain intelligence about what the attacker knows.

Never Trust Claimed Decryption Access Without Verification

A criminal claiming to possess a decryption key should not automatically be believed.

If an organization is considering any negotiation, it should involve qualified incident-response and legal professionals.

A legitimate recovery process should establish what can actually be recovered and what evidence supports the claim.

The goal should be to reduce uncertainty—not create another payment obligation.

What Undercode Say:

  1. Ransomware Is Becoming an Ecosystem, Not a Single Attack

The Ransom Busters case illustrates how ransomware is evolving beyond simple encryption-and-extortion attacks.

  1. Criminals Can Compete Over the Same Victim

A single compromised organization can become valuable to multiple criminal participants.

  1. Timing May Be More Valuable Than Branding

The fact that an alleged recovery service knows about an unpublished attack is potentially more revealing than the name it uses.

4. “Recovery” Can Become Another Social-Engineering Layer

Victims are vulnerable immediately after an incident, making them attractive targets for additional deception.

5. Ransomware Negotiation Is Becoming More Complex

Organizations may no longer be dealing with one criminal decision-maker.

6. RaaS Creates Internal Trust Problems

Affiliates and operators depend on each other, but financial incentives can encourage participants to steal from one another.

7. Stolen Data Has Multiple Possible Buyers

Even when ransomware negotiations stop, stolen information may remain valuable.

  1. A Decryption Key Is Not the Same as Data Deletion

Recovering encrypted files does not guarantee that stolen information has disappeared.

9. Data Extortion Creates Long-Term Risk

A company can restore systems and still face privacy, legal, regulatory, and reputational consequences.

10. Criminals Can Weaponize Confidentiality

Knowing that an attack has not yet become public gives an attacker enormous psychological leverage.

  1. Victims Need an Independent Source of Truth

During an incident, organizations should avoid making critical decisions based solely on unsolicited messages.

12. Incident Response Should Start With Evidence

Every suspicious message, account, hostname, process, and connection can help reconstruct the attack.

13. Legitimate Tools Can Become Attack Infrastructure

SoftPerfect Network Scanner and remote-management software are examples of tools that can have legitimate purposes while also being abused.

14. Tool-Based Detection Is Not Enough

Security teams need behavioral correlation rather than simple malware signatures.

15. Attackers Reuse Habits

The repeated password and hostname described by GRIT demonstrate why operational patterns can be valuable forensic evidence.

16. Small Indicators Can Become Big Clues

A hostname may look meaningless until it appears across multiple investigations.

17. Valid Credentials Remain Dangerous

Once attackers have legitimate credentials, conventional prevention mechanisms can become significantly less effective.

18. Identity Security Deserves Priority

MFA, privileged-access management, conditional access, and strong authentication controls are essential defenses.

  1. Ransomware Defense Must Continue After Initial Access

Stopping the initial intrusion is only one part of the problem.

20. Lateral Movement Must Be Monitored

Attackers frequently need to move through the environment before deploying ransomware.

21. Exfiltration Is Often the Bigger Business

Encryption creates immediate disruption, but stolen data creates prolonged leverage.

  1. Criminals May Monetize the Same Data Repeatedly

The possibility of competing demands shows why data governance matters during ransomware response.

23. Paying Does Not Restore Trust

A payment can potentially satisfy one party without controlling every copy of stolen information.

24. Ransomware Victims Need Crisis Discipline

Fear encourages rushed decisions.

25. Attackers Understand That Fear

The most effective extortion campaigns combine technical damage with psychological pressure.

26. Fake Recovery Offers Exploit That Pressure

A message promising a fast solution can be extremely persuasive when executives are facing operational paralysis.

27. Security Teams Should Validate Every Claim

A claim of access to a decryption key should be independently assessed.

28. Email Intelligence Can Help Investigators

Headers, timestamps, sender infrastructure, and language patterns can contribute to attribution.

29. SIEM Visibility Is Critical

Centralized logs can expose patterns that individual endpoints cannot.

30. Endpoint Telemetry Should Be Retained

Without historical telemetry, investigators may never see how the attacker moved.

31. Cloud Logs Matter Too

Modern ransomware operations frequently involve cloud accounts and storage services.

32. RaaS Fragmentation Could Increase Criminal Infighting

The more participants involved, the more opportunities exist for unauthorized monetization.

33. Defenders Can Exploit That Complexity

Criminal ecosystems generate infrastructure, identities, communication patterns, and operational artifacts.

34. Attribution Requires Multiple Evidence Sources

No single hostname, password, or tool proves who conducted an attack.

35. Correlation Creates Confidence

Repeated behaviors across separate incidents can become much more meaningful when analyzed together.

36. Ransomware Negotiation Needs Cybersecurity Expertise

Financial negotiation without technical verification can expose victims to additional manipulation.

37. Recovery Companies Need Stronger Identity Verification

Organizations should verify who they are communicating with before disclosing sensitive incident information.

38. The First Contact May Reveal the

The information contained in an unsolicited message can help responders understand what the adversary already knows.

  1. The Ransom Busters Case Is a Warning

Even if every attribution detail is not ultimately confirmed, the behavior described by researchers represents a serious emerging threat pattern.

40. The Real Battle Is Over Trust

Ransomware has always attacked availability and confidentiality. This emerging model attacks something else: the victim’s ability to determine whom to trust during the crisis.

✅ Ransom Busters Was Reported Contacting Ransomware Victims

The supplied report states that GuidePoint

The important distinction is that these communications reportedly occurred in some cases before the attacks became publicly known.

✅ GRIT Identified Technical Overlaps

The report says researchers observed overlapping tools and attacker behaviors across incidents, including SoftPerfect Network Scanner, s5cmd, Remotely, a recurring local account password, and the hostname DESKTOP-BBETH6K.

These overlaps were used as part of

⚠️ The Ransom Busters Attribution Is Not Presented as Absolute Fact

GRIT reportedly assessed with moderate confidence that Ransom Busters is a ransomware affiliate attempting to profit outside normal RaaS arrangements.

That wording matters: the conclusion is an intelligence assessment, not definitive proof that every Ransom Busters communication came from the same attacker.

❌ Paying Ransom Busters Should Not Be Treated as Guaranteed Recovery

The report provides no basis for assuming that paying the alleged intermediary guarantees permanent deletion of stolen data or successful decryption.

In fact, the existence of multiple parties with potential access to the same victim information makes such guarantees especially difficult to trust.

Prediction

(-1) Ransomware Victims Will Face More Complicated Extortion Attempts

The ransomware economy is becoming increasingly fragmented, and that fragmentation creates opportunities for criminals to monetize access in unconventional ways.

If affiliates discover that they can secretly approach victims, sell recovery promises, or demand additional payments, similar schemes could become more common.

The biggest consequence may not be higher ransom demands. It may be greater uncertainty about who actually controls the victim’s data.

(+1) Defensive Intelligence Will Become More Effective

The same complexity that benefits attackers can also create forensic opportunities for defenders.

Repeated hostnames, credentials, tools, infrastructure, cloud accounts, and behavioral patterns can help security researchers connect apparently unrelated attacks.

As ransomware investigations become more data-driven, organizations with strong endpoint, identity, network, and cloud telemetry will have a much better chance of identifying these overlaps.

(-1) Criminal Competition Could Increase Pressure on Victims

If ransomware affiliates begin competing with their own operators for additional payments, victims could receive multiple demands during the same incident.

That could make already chaotic negotiations even more difficult.

(+1) Independent Incident Response Will Become More Important

Organizations will increasingly need independent cybersecurity professionals to determine what happened before responding to unsolicited recovery offers.

The safest assumption during a ransomware crisis is simple: every unexpected party claiming to have the solution must be independently verified.

The Bigger Lesson: In Ransomware, the “Rescuer” May Be Part of the Threat

The Ransom Busters investigation highlights an uncomfortable evolution in cybercrime.

Ransomware attacks are no longer necessarily a simple conversation between one criminal group and one victim.

They can involve affiliates, operators, access brokers, negotiators, infrastructure providers, data thieves, recovery scammers, and other intermediaries—all competing for money generated from the same compromised organization.

That creates a new battlefield.

The attacker does not only want to encrypt your systems.

The attacker wants control over the information surrounding the crisis.

They want to know whether you are prepared to pay.

They want to know whether you have backups.

They want to know whether the breach has become public.

They want to know who is negotiating.

And, potentially, they want to convince you that they are the only person who can save you.

That is why the reported Ransom Busters activity deserves attention.

Whether the group’s precise identity and relationship to the ransomware ecosystem are ultimately confirmed or not, the underlying tactic is dangerous: exploiting a victim’s desperation before the incident has even become public.

For defenders, the response is not to panic.

It is to investigate.

Preserve evidence. Validate identities. Protect credentials. Monitor for lateral movement. Review cloud activity. Examine stolen-data exposure. Record every unsolicited communication. And above all, never assume that the person offering the fastest way out is necessarily working in your interests.

In the modern ransomware economy, trust itself has become an attack surface.

▶️ Related Video (74% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube