Suspected ransomware affiliate used fake recovery firm 'Ransom Busters' to demand payments from victims

A suspected ransomware affiliate is posing as a data recovery company called Ransom Busters and contacting ransomware victims before their attacks become public. GuidePoint Security and Coveware say the actor claimed it could provide decryption keys and delete stolen data for fees of $20,000 to $60,000, citing supposed access to ransomware-as-a-service panels for groups including DragonForce, Settra, and Anubis. Investigators linked incidents through overlapping tools and tactics, including SoftPerfect Network Scanner, s5cmd, Remotely, a backdoor account using the password 'Numlock!123,' and the hostname 'DESKTOP-BBETH6K.'
Why it matters: This raises the risk for ransomware victims because paying one party may no longer mean stolen data stays contained. Organizations hit by ransomware should route all negotiation and recovery decisions through trusted incident responders and be wary of unsolicited 'recovery' offers claiming insider access to decryptors or stolen files.

Sources

Ransomware crook poses as recovery firm to steal payments from fellow extortionists
2026.08.20 97% relevant
This article is a direct update on the same Ransom Busters scheme, adding GuidePoint's linkage of the activity to attacks associated with DragonForce, Settra, and Anubis and specific intrusion overlaps including SoftPerfect Network Scanner, s5cmd uploads to AWS, Remotely deployment via PowerShell, reuse of the local account password 'Numlock!123,' and the hostname 'DESKTOP-BBETH6K.'
Rogue ransomware affiliate poses as data recovery firm to steal payments
Lawrence Abrams 2026.08.19 100% relevant
This article establishes a distinct story about a named fake recovery operation, Ransom Busters, and the specific affiliate behavior of intercepting non-public ransomware incidents to siphon payments.
Rogue ransomware affiliate poses as recovery firm to steal payments
Lawrence Abrams 2026.08.19 98% relevant
This article directly updates the same event by adding incident-response observations from GuidePoint and Coveware, including overlap in tooling and tradecraft, the use of the password 'Numlock!123' and hostname 'DESKTOP-BBETH6K', and the specific RaaS brands named in the pitches: DragonForce, Settra, and Anubis.
← Back to all stories