Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
AI-summarised brief · reviewed before publication
A ransomware affiliate operating under the name Ransom Busters is proactively contacting victim organizations to offer data deletion services for fees between $20,000 and $60,000. The group claims to have breached ransomware-as-a-service servers, including those of DragonForce, Settra, and Anubis, to locate stolen data. GuidePoint Research and Intelligence Team identified this behavior as anomalous, noting that legitimate firms typically engage only after attacks become public. Evidence suggests Ransom Busters is likely a criminal actor rather than a legitimate third party, citing violations of the U.S. Computer Fraud Abuse Act. Investigators found striking similarities across incidents, including identical backdoor credentials and hostnames, indicating a single operator. The group argues that unpaid assistance would jeopardize their unauthorized access to criminal infrastructure. Experts warn victims against trusting these offers, as they represent deceptive tactics designed to extract additional extortion payments from organizations already suffering from cyberattacks.
💡 Why It Matters
- · This scheme exploits victim desperation by masquerading as a rescue service, effectively doubling the financial burden on compromised organizations.
- · It reveals how ransomware affiliates are monetizing their own illicit access to criminal infrastructure, turning the recovery process into a secondary extortion vector.