Ransom Busters is a suspected ransomware affiliate persona that masquerades as a ransomware recovery service and contacts victims of active, non-public ransomware incidents. The actor claims it can provide decryption keys and arrange deletion of stolen data in exchange for payment, presenting itself as an intermediary with access to ransomware operators’ infrastructure. Incident-response findings indicate with moderate confidence that this is not a legitimate recovery firm but likely a single affiliate involved in the underlying intrusions and attempting to divert extortion payments away from ransomware-as-a-service operators. The activity has been associated with incidents involving the DragonForce, Settra, and Anubis ransomware ecosystems. Across observed cases, investigators identified overlapping tradecraft and infrastructure, including the use of network scanning, remote monitoring and management tooling, cloud-oriented data transfer utilities, creation of backdoor local accounts, and reuse of the same attacker-controlled host naming. This pattern supports the assessment that one affiliate operated across multiple ransomware programs rather than an independent third party. Ransom Busters’ extortion model centers on pre-publication outreach to victims, offering decryption assistance and purported deletion of stolen data for a fee. This behavior indicates access to victim data and incident details before public disclosure and reflects a form of side-channel monetization within the ransomware affiliate ecosystem. The actor’s conduct increases victim risk because payment to either the affiliate or the primary ransomware operation may not ensure that all parties with access to stolen data will delete it or refrain from leaking it. No high-confidence evidence is available that Ransom Busters is a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A suspected ransomware affiliate masquerading as a recovery service to contact victims of non-public ransomware incidents, claiming access to decryption keys and stolen data and attempting to extract side payments while leveraging access obtained through ransomware affiliate activity.
A suspected ransomware affiliate posing as a recovery service to contact victims of non-public ransomware incidents, claiming access to decryption keys and stolen data and offering deletion/decryption services for payment. Researchers assess it is likely the affiliate behind the attacks and may be attempting to divert ransom payments from RaaS operators.
A ransomware affiliate assessed to be posing as an incident-recovery service in order to monetize victims outside the normal ransomware-as-a-service payment structure and divert ransom negotiations/payments away from the original ransomware operators.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.