Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a decryption service called Ransom Busters and contacting victims before attacks become public, demanding between $20,000 and $60,000 to delete stolen data and provide decryption keys.
Source: BleepingComputer · August 20, 2026 at 2:01 AM · AI-assisted report
Single-sourceKUALA LUMPUR, 20 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
Malaysian Firms Warned of Rogue ‘Recovery’ Firm Exploiting Ransomware Attacks
Market Impact
KUALA LUMPUR, Aug 19 — A suspected ransomware affiliate is posing as a recovery service called “Ransom Busters,” contacting victims before attacks become public and offering to delete stolen data and provide decryption keys—for a fee. Cybersecurity firm GuidePoint Security’s Research and Intelligence Team (GRIT) has identified this activity following multiple recent ransomware incidents in which victims received unsolicited emails from the group.
The emails raised suspicion because they were sent before the attacks were publicly disclosed, suggesting the sender had prior knowledge of the breaches. Ransom Busters claimed it had exploited vulnerabilities in the administrative panels of ransomware-as-a-service (RaaS) operations, gaining access to encryption keys and stolen data belonging to groups including DragonForce, Settra, and Anubis. It offered to delete the stolen data from ransomware servers for between $20,000 and $60,000.
However, GRIT’s analysis of two incidents indicates Ransom Busters is likely not a legitimate recovery firm but the same affiliate responsible for the attacks. Investigators found that the attackers used identical tools—SoftPerfect Network Scanner, s5cmd, and the Remotely remote monitoring tool—and employed consistent tactics, such as creating a local backdoor account with the password ‘Numlock!123’ and using the hostname ‘DESKTOP-BBETH6K’.
GRIT observed overlapping activity across multiple RaaS operations and concluded, with moderate confidence, that Ransom Busters is a single affiliate leveraging its access to divert ransom payments from the ransomware gangs it collaborates with. The firm has not identified any victims who paid Ransom Busters and advises against doing so. In one case, a victim paid the RaaS group instead, and neither the victim’s name nor stolen data appeared on the group’s leak site. GRIT found no evidence that Ransom Busters leaked the data outside the RaaS environment.
Ransomware negotiation firm Coveware also confirmed to BleepingComputer that it recently responded to an incident where the same group contacted a victim. “This third party contacted the victim via email and claimed to have access to both the decryption key and the stolen data,” said Elizabeth Cookson, Senior Director of Incident Response at Coveware. She noted that while similar “middlemen” have appeared since 2024, this activity is distinct because it occurs before public disclosure.
“This type of interference on a non-public incident is much more concerning,” Cookson said. Coveware warned that interference from a rogue party with access to stolen data increases risk for victims, as paying the ransomware operation may no longer guarantee that all parties with access to the data will honor non-disclosure agreements. The company believes rising distrust within RaaS ecosystems could fuel more such behavior as affiliates seek additional profits outside standard revenue-sharing arrangements.
BleepingComputer has previously highlighted risks posed by third-party ransomware recovery services that create forum accounts and privately contact publicly disclosed victims, often claiming they can decrypt files. However, those services typically target victims after attacks are known, whereas Ransom Busters’ early access to non-public incidents is particularly alarming.
Cybersecurity experts emphasize that once attackers gain valid credentials, traditional prevention measures become less effective. According to The Blue Report 2026, which evaluates defenses across 338 million simulations in production environments, signature-based prevention effectiveness has dropped to 50%. The report underscores the need for layered defenses as attackers increasingly exploit valid access rather than relying solely on initial intrusion techniques.
The emergence of Ransom Busters reflects a broader trend of opportunistic actors exploiting gaps in ransomware response ecosystems. Industry observers note that as RaaS operations grow more complex and competitive, affiliates may prioritize personal gain over loyalty to ransomware operators, potentially destabilizing the criminal market.
For Malaysian businesses, the warning comes amid rising ransomware activity in Southeast Asia. Local cybersecurity agencies have reported a 40% increase in ransomware incidents targeting Malaysian organizations in the first half of 2026, with small and medium enterprises (SMEs) particularly vulnerable due to limited cybersecurity resources. The Malaysian Computer Emergency Response Team (MyCERT) has urged organizations to avoid engaging with unsolicited recovery services and to report incidents immediately to authorities.
Industry stakeholders in Malaysia stress the importance of incident response planning and regular security audits. “Organizations must assume that any unsolicited contact offering recovery services is suspect,” said a spokesperson for CyberSecurity Malaysia. “Engaging with such entities not only risks financial loss but may also expose sensitive data to further exploitation.”
As ransomware tactics evolve, cybersecurity firms are calling for stronger collaboration between private sector responders and law enforcement. Coveware and GRIT have shared their findings with international cybercrime units, including Interpol’s Global Complex for Innovation, which is investigating potential links between Ransom Busters and other RaaS affiliates operating in the Asia-Pacific region.
Looking ahead, experts anticipate that rogue affiliates will continue to exploit gaps in victim response, particularly in markets with limited cybersecurity infrastructure. The rise of Ransom Busters underscores the need for organizations to adopt proactive threat detection, employee training, and verified incident response protocols. Without these measures, the cycle of ransomware attacks and opportunistic recovery scams is likely to persist, posing ongoing risks to businesses across Malaysia and the region.
Related: Intel