logo

Ransomware crook poses as recovery firm to steal payments from fellow extortionists

ID: 4eef0217-bb48-50bf-8b69-040b8eef1853

STIX ID: report--4eef0217-bb48-50bf-8b69-040b8eef1853

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

...
...

Researchers at GuidePoint Security discovered an actor calling itself "Ransom Busters" that contacts ransomware victims offering cheaper recovery and data-deletion services while likely being an affiliate who redirects ransom payments; forensic evidence (shared tools, a reused password, and a common hostname) links this activity across multiple RaaS groups and suggests an affiliate is skimming payoffs from criminal partners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.