logo

'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service

ID: bda68862-a1cf-5d19-96cd-b37d473ca0a7

STIX ID: report--bda68862-a1cf-5d19-96cd-b37d473ca0a7

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-08-18

Date Updated: 2026-08-19

Author: Alexander Culafi

...
...

GuidePoint Research observed a malicious actor calling itself “Ransom Busters” contacting ransomware victims and offering to return or delete stolen data for fees ($20k–$60k), claiming access to affiliates’ servers and encryption keys; GRIT assesses with moderate confidence this is likely a ransomware affiliate exploiting shared access to monetize victims outside standard RaaS payment channels, undermining the RaaS business model and posing an active extortion risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.