Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Leaked Stripe Merchant API Keys Expose Payment and Payout Capabilities
August 19, 2026
AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
August 19, 2026
China Hackers Use Malicious VHD Disguised as JPEG to Deploy QUICAgent Backdoor
August 19, 2026
Home/Threats/Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000
Threats

Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000

Key Takeaways Ransomware victims are being targeted by a deceptive new scheme where attackers impersonate data recovery firms. The fake recovery firm, “Ransom Busters LTD,” contacts...

David kimber
David kimber
August 19, 2026 4 Min Read
3 0

Key Takeaways

  • Ransomware victims are being targeted by a deceptive new scheme where attackers impersonate data recovery firms.
  • The fake recovery firm, “Ransom Busters LTD,” contacts victims with knowledge of their private breach and demands a second payment ranging from $20,000 to $60,000.
  • Security researchers believe these “recovery firms” are likely ransomware affiliates attempting to double-extort victims by leveraging their initial access and stolen data.
  • Common tools and tactics observed across multiple incidents suggest a single affiliate group is behind the Ransom Busters persona, operating alongside ransomware operations like DragonForce, Settra, and Anubis.
  • Organizations should treat unsolicited recovery offers with extreme suspicion and involve trusted incident response teams and law enforcement.

Ransomware Hackers Pose as Recovery Firm

A disturbing new trend has emerged in the ransomware landscape, where victims, already reeling from a cyberattack, are being approached by entities masquerading as legitimate data recovery firms. These deceptive operations, exemplified by one calling itself “Ransom Busters LTD,” aim to exploit victims’ vulnerability by offering to retrieve encrypted files and erase stolen data, only to demand a second ransom payment. This tactic adds a complex layer of deception and financial strain to an already critical situation.

Table Of Content

  • Key Takeaways
  • Ransomware Hackers Pose as Recovery Firm
  • The Deceptive Sales Pitch
  • Shared Tools Reveal a Likely Affiliate
  • What You Should Do

The modus operandi involves contacting affected companies before the breach becomes public, specifically requesting to engage with chief executives or IT leaders. This immediate access to sensitive information about a private incident raises significant red flags, suggesting an intimate connection to the original attack. According to a report, researchers suspect these alleged recovery services are, in fact, ransomware affiliates employing a new tactic for extortion.

The Deceptive Sales Pitch

Ransom Busters LTD claims to have penetrated criminal servers, located stolen data, and secured access to encryption keys. They promise to restore victim files and permanently delete all copies held by the original ransomware group, positioning themselves as saviors rather than secondary aggressors. However, their subsequent demand for payment, ranging from $20,000 to $60,000 to “remove” the stolen information, exposes their true intent. The fact that they can demonstrate access to the same dataset as the ransomware affiliate strongly undermines their narrative of being an independent helper.

This scheme presents significant legal and practical dilemmas for victims. Engaging with such an entity, particularly if their claims of infiltrating criminal infrastructure are true, could potentially violate laws like the Computer Fraud Abuse Act. Furthermore, a legitimate recovery provider would not typically demand payment for actions that could be construed as illegal or for services that lack a clear, verifiable outcome. The flimsy justification for the fee – that free assistance would jeopardize their access to criminal infrastructure – further suggests an attempt to manipulate negotiations for financial gain. This pattern indicates a sophisticated effort to redirect ransom payments, fitting within a broader ecosystem where ransomware affiliates often share infrastructure but compete for profits.

Shared Tools Reveal a Likely Affiliate

GuidePoint Security said in a report shared with Cyber Security News (CSN) that their incident response team investigated two separate cases where Ransom Busters contacted victims. The forensic analysis of these intrusions revealed a striking consistency in the tools employed for network discovery, cloud data exfiltration, and remote control. Despite the availability of numerous alternative tools for each task, the attackers utilized the same specific suite:

  • Network discovery: SoftPerfect Network Scanner
  • Data exfiltration: s5cmd for transferring data to AWS cloud storage
  • Remote management: Remotely, installed via a PowerShell script

Additionally, both environments exhibited the same local backdoor account password, “Numlock!123“, and the identical attacker-controlled computer name, “DESKTOP-BBETH6K“. While no single shared tool definitively identifies an attacker, the combination of these consistent overlaps across different ransomware-as-a-service (RaaS) operations (including DragonForce, Settra, and Anubis) led researchers to conclude with moderate confidence that a single affiliate is operating the Ransom Busters persona across these incidents.

The recurring involvement of DragonForce is particularly notable. Their operational model, detailed in a DragonForce attack technique review, illustrates its cartel-style services, including dedicated panels and storage for its partners, which could facilitate such double-extortion schemes.

What You Should Do

For organizations that have fallen victim to ransomware, receiving an unsolicited recovery offer can be tempting, but it is crucial to exercise extreme caution.

  • Engage your incident response team: Immediately forward any suspicious recovery messages to your internal or external incident response team for analysis and preservation as evidence.
  • Involve law enforcement: Report the incident to relevant law enforcement agencies. They can provide guidance and potentially aid in investigations.
  • Verify claims independently: Do not trust claims of data access or deletion without independent verification. A legitimate recovery firm would not engage in illicit activities or provide questionable justifications for payment.
  • Assume no guarantees: Understand that paying a self-proclaimed “recovery firm” offers no assurance that stolen data will be erased or that further extortion attempts will cease. You may simply

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackBreachHackerransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical macOS Screen Sharing Vulnerability Actively Exploited

Next Post

CISA Adds Critical Microsoft SharePoint Auth Bypass (CVE-2023-29357) to KEV

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000
August 19, 2026
Critical macOS Screen Sharing Vulnerability Actively Exploited
August 19, 2026
MacSync Stealer Uses 30+ Domains to Steal Passwords and Sensitive Mac Data
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us