2026-08-20NOTABLEThe tell is the timing: a recovery offer that arrives while the intrusion is still private is foreknowledge, not marketing
Ransom Busters
actor · actor:ransom-busters
Persona that emails ransomware victims before their incident is public, posing as an independent recovery service and offering to return files and delete stolen data for $20,000-$60,000. GuidePoint Security's research team assesses with moderate confidence that it is a single ransomware affiliate working across several ransomware-as-a-service programmes and diverting payments from them, on the basis of an identical tooling and artefact set recurring across incidents attributed to different brands (GuidePoint Security, 2026-08-18).
Aliases: Ransom Busters LTD
Coverage
1
first 2026-08-20 → last 2026-08-20
Latest activity
2026-08-20
The tell is the timing: a recovery offer that arrives while the intrusion is still private is foreknowledge…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts
Defender insights
What each entry about Ransom Busters tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
collaborates with
- Anubis (ransomware-as-a-service)named by GuidePoint alongside DragonForce and Settra as a programme whose incidents carried the same outreach
- DragonForceGuidePoint states it observed the Ransom Busters outreach while responding to incidents involving DragonForce, and assesses the persona is an affiliate employed across the programmes it targets
- Settranamed by GuidePoint alongside DragonForce and Anubis as a programme whose incidents carried the same outreach
Story timeline
Hunting pivots
ATT&CK techniques (6 across 6 tactics)
6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionCommand and Scripting Interpreter: PowerShell
- PersistenceCreate Account: Local Account
- DiscoveryNetwork Service Discovery
- Command and ControlRemote Access Tools
- ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactFinancial Theft
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Persistence TA0003
T1136.001Create Account: Local Account×1
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Discovery TA0007
T1046Network Service Discovery×1
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Exfiltration TA0010
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Impact TA0040
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Entries about Ransom Busters (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (50%)
- guidepointsecurity.com1 (50%)