The rescue email arrives before the breach is public
A firm called Ransom Busters offers to delete stolen data for $20,000 to $60,000. GuidePoint assesses it is the affiliate that took the data in the first place.
Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.
A company gets encrypted. Before anyone outside the building knows, an email lands with the chief executive from a firm offering to delete the stolen data and return the files. The price is between twenty and sixty thousand dollars [1].
The breach is not public. There is no leak site post, no press coverage, nothing a stranger could have read.
That detail is the entire story, and it is the one a company in the first days of an incident is least equipped to notice.
What happened
GuidePoint’s research team responded to several ransomware incidents where the victim received an unsolicited email from an entity calling itself Ransom Busters [1].
The pitch is confident. The sender claims to have spent over three years finding vulnerabilities in criminal infrastructure, says it recently accessed a server holding data stolen from the recipient’s company, and offers to destroy that data and supply decryption [1]. Emails go to chief executives and IT leadership at domain addresses [1].
GRIT found the same actor contacting victims of three separate ransomware operations: DragonForce, Settra and Anubis [1].
Then they looked at the intrusions themselves, and the pieces stopped fitting the story the emails told.
Across two incidents, GRIT found identical tooling and identical artifacts: the same commodity network scanner, the same cloud storage transfer utility used for exfiltration, the same remote management tool, the same password on backdoor accounts, and the same hostname appearing inside different victims [1][2].
GRIT assesses with moderate confidence that Ransom Busters is not a third-party victim services firm, but a single ransomware affiliate working across multiple ransomware-as-a-service operations [1].
Read plainly: the researchers believe the firm offering to delete your stolen data is the person who took it.
GuidePoint has not confirmed that any victim paid Ransom Busters. In one case a victim paid the ransomware operation instead, and the data was not subsequently published [2].
Why this matters
The timing is the tell, and it is the only one available early. Security firms do approach ransomware victims cold. That business exists and most of it is legitimate, if occasionally tasteless. What it cannot do is arrive before the incident is public, because that is how those firms find out. Coveware, quoted in reporting on the campaign, draws the same line and calls interference in a non-public incident considerably more concerning than ordinary ambulance chasing [2].
It targets the worst hour of the worst week. The email goes to executives, not to the security team, and it arrives while the company is still working out what happened. Somebody senior, frightened, and days away from having good information is being offered a way to make it stop. That is not a technical vulnerability and no patch addresses it.
It quietly undermines the logic of paying at all. Whatever you think of ransom payment as a decision, it rests on the assumption that the operation you are negotiating with controls the stolen data. If an individual affiliate keeps a copy and will sell it separately under another name, then a deletion assurance from anybody is worth less than it looked [2].
Technical breakdown
The intrusions themselves are unremarkable, and that is worth saying because the interesting part is what happens after.
- Initial accessThe affiliate compromises the victim on behalf of a ransomware operation
- DiscoveryThe estate is mapped with a commodity network scanner rather than custom tooling
BREAK THE CHAIN HERE
Alert on network scanning utilities running from workstations and servers that have no administrative role. These are legitimate tools, so hunt on where they run rather than on the binary alone. - ExfiltrationData is copied out using a cloud storage transfer utility
BREAK THE CHAIN HERE
Restrict and monitor outbound traffic to cloud object storage from servers that hold sensitive data. Alert on high volume transfers to storage endpoints your organisation does not use. - ImpactThe ransomware operation encrypts and begins its own extortion, on its own timeline
- PivotThe same affiliate contacts the victim separately, presenting as an unrelated recovery firm
BREAK THE CHAIN HERE
Route every inbound communication about the incident to whoever is running it. No executive negotiates from their own inbox, and nobody replies to an unsolicited sender to ask questions. - PretextThe email claims years of infiltrating criminal servers and possession of the victim's data
- Second demandTwenty to sixty thousand dollars is requested to delete the data and provide keys
- OutcomePayment, if made, goes to the affiliate rather than the operation, and no source establishes that data is deleted either way
The artifacts that connected it
This is the part I found most useful, because it is a reminder of how attribution actually gets done. GRIT did not break any encryption or unmask anybody. They noticed that two separate victims contained the same fingerprints [1][2]:
- SoftPerfect Network Scanner for internal discovery
- s5cmd, a fast command line tool for cloud object storage, used to move data out
- Remotely, a remote management tool, for access
- The password Numlock!123 on backdoor accounts, in both intrusions
- The hostname DESKTOP-BBETH6K, appearing inside different victims
The first three are legitimate software with legitimate uses, which is exactly why they get chosen. The last two are the ones that matter for hunting, because a reused password and a reused hostname are operator habits rather than tools, and habits are harder to change than tooling.
If you have historic incident data, those two strings are worth a search. A hostname belonging to an attacker’s own machine turning up in your environment is not something with an innocent explanation.
What is not established
GRIT does not confirm any victim paid Ransom Busters, does not establish whether data is deleted when anyone pays, and does not say how many victims were contacted [1]. Whether the named operations know they are being undercut by one of their own affiliates is unaddressed. I could not obtain the emails themselves, so the wording here is as GRIT reproduced it.
What defenders should do Monday morning
Immediate, within 24 hours. Tell your executives this exists, in one sentence, before they need to know. The email is designed for somebody who has never heard of it and is having the worst week of their career. A chief executive who has been warned will forward it. One who has not may reply.
Near term, this week. Write down who is allowed to communicate with anyone claiming involvement in an incident, and make the answer a named role rather than whoever received the message. Add a line to your incident plan covering unsolicited third-party contact: preserve it with headers, do not reply, hand it to the incident lead, report it. CISA’s ransomware guidance covers reporting and notification channels and is the reference to point at rather than inventing your own [3].
Structural, this quarter. Decide your ransom payment position while nothing is on fire, including who is authorised to decide and what evidence would be required. An organisation that has never had that conversation will have it under duress, with an attacker helping. Then look at outbound access to cloud object storage from your sensitive systems, since exfiltration through legitimate cloud tooling is what made the second demand possible at all.
Checklist
- Executives briefed that fake recovery outreach exists and what to do with it
- A named role owns all incident-related external communication
- Incident plan covers unsolicited third-party contact: preserve, do not reply, escalate, report
- Ransom payment position and decision authority agreed in advance
- Historic incident data searched for the reused hostname and backdoor password
- Alerting for network scanning utilities on hosts with no administrative role
- Outbound cloud object storage access restricted and monitored from sensitive systems
- Reporting route to law enforcement identified before it is needed
The industry left this door open
There has always been a murky end of ransomware recovery. Firms that advertise proprietary decryption and quietly pay the ransom, marking it up and telling the client nothing. That practice has been documented for years and has been treated mostly as an ethics problem, embarrassing rather than dangerous.
It is the reason this works.
A market where victims already expect recovery vendors to be opaque about their methods, and to appear unbidden during a crisis, is a market where an email from a stranger claiming secret access to criminal infrastructure does not immediately read as absurd. The pretext borrows credibility the industry manufactured and declined to clean up.
Vendors who will not say plainly whether they pay ransoms are not committing this fraud. They built the conditions where it sounds plausible, and the bill for that is landing on victims who cannot tell the difference in the middle of their worst week.
FREQUENTLY ASKED
- How would we tell a real recovery firm from this?
- Start with timing. Legitimate firms approach after an incident is public, because that is when they learn about it. Contact that arrives before disclosure means the sender knows something only the victim and the attacker know, and there are not many innocent explanations for that. Beyond timing, verify through a channel you initiated: a firm you already have a relationship with, your insurer's panel, or law enforcement.
- Is paying them any worse than paying the ransomware group?
- It is the same decision with less information. Paying either party buys a promise about data you cannot verify. The difference is that a ransomware operation has a reputational incentive to honour deals, thin as that is, and an actor freelancing against its own employers has none. GuidePoint has not confirmed any victim paid Ransom Busters.
- Why would an affiliate do this to the group it works with?
- Because the affiliate holds the data and the operation holds the brand. In ransomware-as-a-service the affiliate does the intrusion and takes a cut of what the operation collects. Contacting the victim directly, under another name, is a way to be paid in full rather than in part. GuidePoint frames it as diverting payments from the operations the actor works across.
- Our CEO got an email like this. What now?
- Do not reply, and do not forward it to the sender's address to ask questions. Preserve it with full headers, hand it to whoever is running the incident, and report it. Then treat it as evidence rather than as an offer, because the timing tells you something about who has your data even if the sender's claims are false.
- Does this change how we should think about ransom negotiation?
- It weakens an assumption underneath it. Negotiating with an operation assumes the operation controls the stolen data. If an individual affiliate retains a copy and is willing to monetise it separately, then any assurance about deletion is worth less than it appeared, whoever gives it. Coveware makes a version of this point in reporting on the campaign.
REFERENCES
- [1]Beware the Ransomware Rescuer: Ransom BustersVENDOR RESEARCH
- [2]Rogue ransomware affiliate poses as recovery firm to steal paymentsJOURNALISM
- [3]#StopRansomware GuidePRIMARY
BEFORE YOU GO
Was this useful?
Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.
SEND FEEDBACK ↗