A threat actor calling itself Ransom Busters is contacting ransomware victims before their attacks go public, offering to delete stolen data and restore files in exchange for payments between $20,000 and $60,000, according to research published August 18 by GuidePoint Security’s Research and Intelligence Team (GRIT).
What happened
GRIT assesses with moderate confidence that Ransom Busters is not an independent third party at all, but a single ransomware affiliate that works across multiple ransomware-as-a-service operations and applies the same tactic in each victim environment. The group has surfaced in GRIT’s incident response engagements involving DragonForce, Settra, and Anubis, sending emails to company domains asking to reach a CEO or IT leader, claiming to have infiltrated the original attackers’ infrastructure, accessed their decryption-key storage, and found the victim’s exfiltrated data sitting on it.
Why it matters
The tell GRIT flags is timing: Ransom Busters reaches out before the underlying attack becomes public, which a genuine third-party researcher responding to a disclosed incident would have no way to do. Paying does not verify anything either. A victim has no way to confirm the data was actually deleted or that every party with access to it, including the original ransomware group itself, has relinquished it. GRIT also notes that the claimed offensive access to a rival group’s infrastructure would itself expose a paying organization to potential Computer Fraud and Abuse Act liability.
The original insight
Ransom Busters is best read as evidence that affiliate-model ransomware has enough internal churn to produce freelance actors who extort the same victim twice under different names, the same operational dysfunction CISA’s updated Medusa ransomware advisory this week flags as a pattern to expect from affiliate-run RaaS brands. Incident response plans that assume one extortion contact per incident should be updated to expect a second, unrelated one, and any unsolicited pre-disclosure contact claiming insider access to attacker infrastructure should go straight to legal and the primary incident responder rather than being negotiated independently. It is also worth cross-checking against CyberTech’s coverage of Gunra’s own MFA-bypass tactics, since overlapping initial-access brokers mean today’s extortion actor can be tomorrow’s unrelated intrusion.
Source: GuidePoint Security GRIT