Ransom Busters Adds a Fake Recovery Layer

GuidePoint Research and Intelligence Team (GRIT) found a cybercriminal affiliate calling itself Ransom Busters emailing victims of DragonForce, Settra, and Anubis, claiming access to gang servers, keys, and stolen data. The pitch asked for $20,000 to $60,000 to recover files or delete data, while the attacks were still not public. The trick is a second payment scheme wrapped in rescue language. The message borrows the look of incident-recovery help, but the claimed access is the leverage: pay us, and we will supposedly hand back files or erase copies held by the ransomware group. That turns recovery outreach into part of the extortion chain, not a break from it. For incident-response teams, that means the identity and timing of anyone offering recovery help now matters as much as the ransom note itself. If a third party appears before an incident is public, the open question is not whether they are helpful, but which criminal side they are trying to monetize.

Sources