Circuit Wire — a daily news update from the Circuit.

An outfit calling itself Ransom Busters has been emailing ransomware victims before their attacks became public, offering to hand over decryption keys and delete stolen data for a fee. GuidePoint Security's Research and Intelligence Team, known as GRIT, disclosed the activity on August 19 after responding to several recent incidents in which victims received the messages.

Ransom Busters told victims it had exploited flaws in the administrative panels used by ransomware-as-a-service operations, giving it access to encryption keys and stolen files. It offered to delete data held on servers belonging to DragonForce, Settra and Anubis for between $20,000 and $60,000, well below the original extortion demands. It also demonstrated access to the same datasets held by the affiliate behind the attacks.

The timing was the first problem. The emails arrived before the attacks had been disclosed anywhere, which raised the question of how the sender knew. Forensic work on two of the incidents pointed to an answer. Both intrusions used SoftPerfect Network Scanner for reconnaissance, the s5cmd utility to move data into AWS cloud storage, and the Remotely remote management tool installed through PowerShell. Both also featured a local backdoor account with the password Numlock!123 and the same attacker-controlled hostname, DESKTOP-BBETH6K.

GRIT assesses with moderate confidence that Ransom Busters is a single ransomware affiliate working across several ransomware-as-a-service programs and steering payments away from the gangs it works for. The researchers say they have seen the same overlapping activity across multiple separate programs, The Register reported, which makes shared tooling a weaker explanation than one affiliate moonlighting.

The ransomware negotiation firm Coveware confirmed it recently handled at least one incident involving the same party. "This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data," Elizabeth Cookson, senior director of incident response at Coveware, told BleepingComputer.

Coveware says it has seen similar middlemen operating under other names as far back as 2024. Those cases involved so-called ambulance chasers who approached victims only after an attack had been publicly disclosed. Contact on an incident that is still private is a different matter, and the firm says interference from a rogue party holding stolen data raises the risk for victims, because paying the operation no longer guarantees that everyone with a copy will honor the agreement.

GRIT says it has not seen any victim pay Ransom Busters and advises against doing so, noting there is no assurance stolen files would actually be deleted. In one case the victim paid the ransomware operation instead. That victim's name and data were not published on the group's leak site, and researchers found no evidence Ransom Busters leaked the material elsewhere.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.