ALITEQ.

There's a new group extorting ransomware victims and it's not the ransomware gang

GuidePoint's threat intel team says the 'recovery firm' emailing breached companies with a $60,000 fix is running the same infrastructure as the original attack.

Priya NairUpdated 2h ago6 min readWeb story
A person typing on a laptop keyboard in a dimly lit room with code visible on screen

If a ransomware gang already stole your files this year, brace yourself — there's a second group now emailing victims pretending to be the good guys. GuidePoint's threat intel team, GRIT, is calling it Ransom Busters, and it isn't a recovery firm at all. It's very likely the same criminals asking to get paid twice: once to encrypt you, once more to "find" the leverage they already had the entire time.

How the scam actually works

The pitch arrives cold, usually by email, and it's specific enough to feel credible. Ransom Busters claims to have quietly breached the administrative panels of major ransomware-as-a-service operations and has been sitting on that access for "over three years." It says it found your company's stolen data sitting on those servers. It offers to delete the backups and hand back your files — for a fee between $20,000 and $60,000, paid directly to them, no negotiation with the original attackers required. It asks, specifically, to be put in touch with your CEO or IT leadership rather than a security team, which tells you exactly who it's trying to pressure.

An email lands at a company that's already been through a ransomware breach.

It claims to have hacked into the ransomware gang's own infrastructure.

It says it can locate and delete your specific stolen data.

It demands $20,000–$60,000, payable to them, not the original attacker.

It asks to speak directly with your CEO or IT leadership, not your security desk.

Who's actually behind Ransom Busters

GuidePoint's GRIT team, led by principal consultant Justin Timothy, connected two separate victim incidents using identical forensic fingerprints: the same SoftPerfect Network Scanner build, the same s5cmd tool used to pull data out to AWS storage, the same remote-monitoring software installed for persistence, a backdoor account with the password "Numlock!123," and an attacker workstation identified by the exact same hostname — DESKTOP-BBETH6K — across incidents. That's not coincidence-level overlap. It's the signature of one operator running both the original intrusion and the follow-up "recovery" pitch.

$20K–$60K

Demanded

per victim, on top of any ransom already paid

3+ years

Claimed access window

an unverified claim inside the extortion email

3

Ransomware brands linked

DragonForce, Settra, and Anubis incidents

4

Shared forensic artifacts

same scanner, exfil tool, backdoor account, and hostname across incidents

A laptop screen showing an email inbox with a suspicious message flagged
GuidePoint's investigators say the 'recovery' pitch traces back to infrastructure already tied to the original intrusion — not an outside rescuer. · Unsplash

This isn't new — it's an old grift with better branding

Fake recovery scams targeting individual ransomware victims aren't a new idea; smaller operators have run "we'll negotiate your ransom down" schemes for years. What's different here is scale and confidence — this reads like a deliberate second product line bolted onto an existing ransomware operation, aimed specifically at victims who are already scared, already burned once, and already primed to believe someone can make the pain stop for a price. That's a genuinely nastier evolution of double extortion, and I'd expect other affiliates to copy it once they see it works.

What to do if you get one of these emails

  • Don't reply from the address it arrived at — verify independently through your incident-response provider first.
  • Treat any 'proof' screenshot as unverified; it may be recycled from a public leak-site post.
  • Loop in legal counsel and your cyber-insurance carrier before any contact happens.
  • Never wire funds on a promise to delete stolen data — no confirmed case of that promise being kept has surfaced.
  • Report it to law enforcement (FBI IC3 in the US, or your national equivalent) — this is extortion, not a service.

Is Ransom Busters a real data-recovery service?
No. GuidePoint's investigators found it shares infrastructure and tooling with the ransomware intrusions it claims to be fixing.
Which ransomware groups' victims are being targeted?
Incidents tied to DragonForce, Settra, and Anubis attacks, according to GuidePoint's GRIT team.
Should I pay if I already paid the original ransom?
There's no good reason to. Researchers found no confirmed case of a criminal group actually deleting exfiltrated data after a second payment.
How can I tell if a recovery-service email like this is legitimate?
Genuine incident-response firms don't cold-email your CEO demanding a specific dollar figure on a deadline. Verify independently before engaging anyone claiming this role.

This fits a wider pattern we've been tracking all month — ransomware crews getting more theatrical about extortion, not less. Cl0p named Shell and Philips among more than 40 victims of a single unpatched flaw, a hospital's own Facebook page got hijacked to brag about a breach, and one gang moved its command infrastructure onto a public blockchain specifically so it couldn't be shut down. Ransom Busters is the same instinct pointed a different direction — squeezing a second payment out of a wound that's already open. If you run incident response for a living, this is the moment to brief your leadership on exactly what a legitimate recovery engagement looks like, before a fake one lands in someone's inbox.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading