Ransom Busters: When a Ransomware Gang Offers to Help You Recover

There is an adage about someone breaking your windows and then knocking on the door, offering a remarkably competitive glazing service. The ransomware ecosystem appears to have adopted a similar strategy.

Researchers from GuidePoint Security's Research and Intelligence Team (GRIT) have identified an entity calling itself Ransom Busters, which approaches organisations in the middle of ransomware incidents, offering what appears to be an incident-recovery service.

In its approach, Ransom Busters claims to have compromised the infrastructure of ransomware groups and obtained access to their administrative systems. It tells victims that it has discovered their stolen data on those systems and that, of course, for a fee, it can return their files, destroy copies held by the ransomware group, and even provide encryption keys.

There is just one rather significant problem: GuidePoint assesses with moderate confidence that Ransom Busters is not an independent security organisation at all. Instead, the researchers believe it is a ransomware affiliate that has participated in attacks and is subsequently approaching the victims itself, attempting to divert ransom payments away from the ransomware operation with which it was working.

There is just one rather significant problem: GuidePoint has concluded that Ransom Busters is not an independent security organisation at all. Instead, the researchers believe it is a ransomware affiliate that has participated in attacks and is subsequently approaching the victims itself, attempting to divert ransom payments away from the ransomware operation with which it was working.

If that assessment is correct, it represents an extraordinary evolution in the economics of ransomware. The criminal who burgled your house is coming back, offering to help with the clean-up and install new locks.

Meet Ransom Busters

The researchers encountered the activity while responding to incidents involving other ransomware groups, including DragonForce, Settra and Anubis.

The initial approach typically arrives by email, which claims that it has compromised ransomware infrastructure and found information belonging to the victim. It then offers to return that information and destroy the copies supposedly held by the ransomware operators for a fee of between $20,000 and $60,000.

When challenged, Ransom Busters was able to demonstrate that it had access to the same dataset possessed by the ransomware affiliate.

This makes their approach considerably more convincing than prior recovery scams, because this is not necessarily somebody scraping news reports, discovering that an organisation has been attacked and sending a speculative email; Ransom Busters appears to possess knowledge of the actual incident.

Across two incidents investigated by the GuidePoint DFIR team, there were significant commonalities in the intrusions, including overlapping reconnaissance, exfiltration, and remote-monitoring tools. Local backdoor accounts even shared a password, while the same attacker-controlled hostname appeared across the attacks. Those overlaps led GRIT to assess that Ransom Busters was likely a single ransomware affiliate operating across multiple Ransomware-as-a-Service groups.

This may not be a recovery scam running alongside the ransomware attack. It may be the ransomware operation monetising the same victim twice.

Ransomware Has Developed Its Own Supply Chain

To understand why this is possible, it helps to understand how dramatically ransomware has changed since the modern ransomware ecosystem emerged just over a decade ago. Technically, ransomware dates back to the AIDS Trojan in 1989, but there was a long hiatus before cryptocurrency helped provide the practical payment mechanism needed to monetise ransomware at scale.

The term "ransomware gangs" is still in common use. This creates an image of a relatively cohesive group of criminals breaking into an organisation, stealing its data, encrypting its systems, and demanding money. Increasingly, that is not how the ecosystem operates.

Modern Ransomware-as-a-Service has become specialised. One actor may discover or purchase the initial access, another conducts reconnaissance and establishes persistence, while an affiliate carries out the intrusion using infrastructure or tooling provided by others. The ransomware payload may come from the RaaS operator, with separate specialists handling negotiation, data publication, and money laundering. It increasingly resembles a commercial supply chain, albeit an illegal one.

That specialisation allows individual participants to work with multiple ransomware operations, but it also creates competing incentives.

The affiliate conducting the intrusion may possess valuable information that the RaaS operator does not exclusively control. The RaaS operator wants its percentage of the ransom, while the affiliate would rather keep more of it, even though ultimately both are trying to monetise the same victim organisation. Seen through that lens, Ransom Busters' strategy starts to make considerably more sense.

If the GuidePoint assessment is correct, the affiliate has realised that rather than simply taking its agreed share of a ransom payment, it can approach the victim directly and offer a cheaper alternative, effectively disintermediating its own criminal supply chain. There is almost something darkly entrepreneurial about it.

The Victim Is Particularly Vulnerable During Recovery

What interests me most is not the internal economics of ransomware. It is the psychological effect of the timing.

When I get dropped into a customer environment after they have suffered a major disruptive cyberattack, I typically witness an extraordinary information vacuum.

Executives want to know when the business will operate again, customers want to understand whether their data has been affected and when services will return, while legal and compliance teams are trying to establish the organisation's exposure and regulatory obligations. Regulators may already be expecting notification, third parties want to know whether contractual commitments will be met and whether they should sever connectivity, and the media may be approaching employees through LinkedIn looking for the inside track.

At the same time, security teams are still trying to determine what actually happened and infrastructure teams are attempting to establish what can safely be restored. All of this is happening while the organisation may not yet understand the full extent of the compromise.

Into that uncertainty arrives someone saying, “we know what happened, we know who attacked you, we have your data and access to the attackers' infrastructure, and we can make the problem go away.”

That is an extremely powerful proposition. Especially when the person making it can demonstrate knowledge of information that should only be available to the attacker.

This is why organisations need to recognise that the attack surface now extends beyond recovery platforms to the recovery services themselves.

Recovery Creates New Opportunities for Social Engineering

Security awareness teams spend considerable time training employees to recognise suspicious emails before an attack, but far less attention is given to how judgement changes once the organisation is already under attack and employees are operating under considerable pressure.

During a major incident, I’ve witnessed normal trust mechanisms becoming distorted, especially in organisations that have not invested enough time and effort into the preparatory steps and developing contingencies. This creates an almost perfect environment for social engineering.

An attacker does not necessarily need to impersonate Microsoft support anymore. They can impersonate the people coming to save you from the attacker.

That means organisations need to think about how they establish trust during recovery before recovery begins.

Who Are You Going to Trust?

Channelling my inner Ghostbuster, one of the questions I regularly encourage organisations to answer before an incident is deceptively simple: “Who are you going to call?”

A shared responsibility model for recovery should be established before an incident occurs. Legal counsel, retained digital forensics and incident response, negotiators, and recovery partners should already be selected, with their activation procedures, responsibilities, and hand-offs tested through realistic drills rather than discovered for the first time during a crisis.

Contracts, activation instructions, and trusted contact details should also be stored somewhere isolated from the infrastructure being attacked, ideally with access that does not depend on the same identity plane as production.

Critically, organisations should also agree in advance how the people involved in recovery will be authenticated. If someone claiming to represent your incident-response provider contacts the crisis team, how do you establish that they genuinely work for that organisation? If somebody claims law enforcement has recovered your data, through which pre-agreed channel do you validate that claim? If an unsolicited “recovery company” approaches executives with detailed knowledge of the incident, who decides whether any engagement takes place?

During an attack, you should not be inventing the trust model at the same time as you are trying to recover the business.

These sound like relatively minor procedural questions. At 10 AM on an ordinary Tuesday, they probably are. At 3 AM on day three of a ransomware attack, with production unavailable and senior executives demanding answers, they become considerably more important.

Proof of Access Is Not Proof of Trust

Another important lesson from Ransom Busters is that the fact that somebody can demonstrate access to your stolen data proves only one thing: They have access to your stolen data.

It does not establish how they obtained the data, whether they control every copy or have the ability to delete it, and it certainly does not demonstrate that they are acting in your interests.

When dealing with Ransomware-as-a-Service, GuidePoint points out that an affiliate may not have unilateral control over all copies of stolen information or the broader extortion infrastructure. Even if Ransom Busters genuinely deleted the copy it could access, the victim has no reliable way of knowing whether another affiliate, the RaaS operator or another criminal retains another copy.

This exposes one of the fundamental weaknesses in the whole ransomware payment proposition: the transaction ultimately depends upon trusting the criminal.

Paying for a decryptor is at least potentially verifiable: you can test whether the key decrypts your data. Paying somebody to delete stolen information is fundamentally different.

That should not be interpreted as an argument for paying a ransom, something I never recommend. Decryptors are typically built for speed rather than integrity and can themselves result in data loss, acquiring cryptocurrency can introduce significant KYC delays, payments may create sanctions exposure, and even receiving the keys can create a major operational problem when you are handed thousands of individual decryption keys, but the CMDB that tells you which key belongs to which machine is itself encrypted.

How do you prove a negative? The criminal can show you that a directory has disappeared, but they cannot demonstrate that the information was never copied somewhere else.

This is why the UK's NCSC makes an important distinction when discussing ransomware: irrespective of whether a ransom is paid, the organisation has already lost control of its information.

Ransom Busters makes that uncomfortable reality particularly obvious.

Trusted Recovery Requires Trusted Relationships

Organisations spend enormous amounts of money establishing trust within production environments. Then a destructive cyberattack occurs, and where recovery has not been properly prepared and exercised in advance, many of those assumptions are dismantled under pressure as teams make rapid changes simply to get the business operating again. The problem is not the need to move quickly; it is being forced to make those decisions for the first time during the crisis, without fully understanding the security, dependency, and trust implications of the shortcuts being taken. That is precisely when trust becomes most important.

Cyber recovery needs its own trust architecture.

That starts with knowing which people and organisations are authorised to participate in recovery, maintaining verified out-of-band contact details, and establishing clean communication channels that do not depend on compromised infrastructure. Emergency identities and privileged access need to be controlled, recovery tooling should be validated before it is introduced into clean environments, and external forensic or recovery providers should only be engaged through trusted, pre-agreed channels. Unsolicited approaches during an incident should be treated as potentially hostile, regardless of how much the sender appears to know about the attack.

The NCSC already recommends organisations establish appropriate incident-response capability and provides an assured Cyber Incident Response scheme for organisations that need external assistance. The principle extends beyond selecting a DFIR company. You should know who you will trust during recovery before an attacker gets the opportunity to make that decision for you.

Ransom Busters also illustrates why I increasingly dislike describing cyber recovery simply in terms of getting systems “running again”. Availability is only one dimension of recovery.

An organisation may successfully restore applications and data but still be unable to establish whether the attacker retains valid credentials, whether persistence remains in the environment, or whether the recovered operating systems, applications, and configurations still expose the same attack surface that enabled the compromise in the first place. Technically, production may be running again; operationally, the organisation may still be compromised.

In the case of Ransom Busters, there is an additional risk: the organisation may also have shared sensitive incident information with another unknown party simply because that party claimed it could help.

Cyber recovery, therefore, needs to restore more than availability. It needs to re-establish trust.

The Criminal Ecosystem Will Continue to Innovate

There is an understandable tendency to think about ransomware innovation in technical terms, but ransomware operators innovate commercially as well.

Ransomware-as-a-Service was itself a business-model innovation, creating a criminal ecosystem in which initial access, tooling, infrastructure, and execution could all be supplied by different specialists. Double extortion added data theft and the threat of publication to encryption, while data-only extortion subsequently demonstrated that encryption was not even necessary if the stolen information created sufficient leverage.

Then came what became known as triple extortion, where the pressure moved beyond the organisation itself. Ransomware operators began contacting customers, suppliers, and business partners, harassing employees and calling senior executives directly to increase the pressure to pay. REvil, for example, announced plans to combine DDoS attacks with calls to journalists and victims’ business partners, while DarkSide was observed escalating from threatening employees to calling senior executives and threatening to contact customers and the press. More recently, that intimidation has crossed into the physical world, with extortion actors using swatting — making false emergency calls designed to send armed law enforcement to executives’ and employees’ homes.

The escalation has even extended to attempting to weaponise regulators. In 2023, ALPHV/BlackCat claimed to have breached MeridianLink and, when the company apparently did not engage with its extortion demands, filed a complaint with the US Securities and Exchange Commission alleging that MeridianLink had failed to disclose the incident. In effect, the attacker that claimed responsibility for causing the breach was attempting to use the prospect of regulatory scrutiny and potential penalties as additional leverage against its victim

Ransom Busters may represent the next experiment in that continuing evolution: having attacked the victim, the criminal ecosystem has now discovered that it may also be possible to monetise the recovery. Whether this particular approach becomes widespread remains to be seen. GuidePoint says it is not aware of a case in which Ransom Busters' tactic has actually succeeded.

But the idea is now out there, which means organisations should assume somebody else will try it.

During a cyberattack, the organisation will be approached by people offering information, assistance, negotiation, recovery, and solutions.

Some will genuinely be there to help; others may be trying to exploit the confusion. The difficulty for an organisation operating under enormous pressure is establishing which is which.

That makes one question fundamental to cyber resilience: “When the systems you normally rely upon to establish trust have themselves been compromised, how will you decide who to trust?

That question needs answering before the incident. As Ransom Busters demonstrates, once the attack begins, the criminals may be more than happy to answer it for you.

Next
Next

The Loom of Doom: What My 35-Year-Old Land Rover Taught Me About Cyber Recovery