# The Double-Cross: A Ransomware Affiliate Is Running a Parallel Extortion Racket as a Fake Recovery Firm
When a company gets hit with ransomware, the playbook is grim but familiar: call your IR firm, assess the damage, negotiate or restore from backup, notify regulators. What victims are not prepared for is a second email — arriving before anyone outside the company even knows they've been hit — from someone claiming to be their savior.
That's the racket GuidePoint Security's GRIT team documented this week. A threat actor calling itself "Ransom Busters" has been contacting ransomware victims with a pitch: pay us $20,000 to $60,000 and we'll get your files back and delete your stolen data from the criminal servers. The twist? Ransom Busters is almost certainly the ransomware affiliate that helped steal the data in the first place.
## How the Scheme Actually Works
The email Ransom Busters sends reads like a legitimate incident-response sales pitch. The group claims it has infiltrated the infrastructure of multiple ransomware operations — specifically DragonForce, Settra, and Anubis — and stumbled across the victim's data. It says it has encryption keys, access to backups, and the ability to make the whole mess disappear. For a fee.
It's a compelling story. It would be even more compelling if it weren't designed to extract a second payment from someone already getting extorted.
The tell that blows the cover: Ransom Busters contacts victims before the attack is publicly disclosed. Incident response firms learn about incidents after clients call them. Ransomware affiliates — the operators who actually breach networks, deploy payloads, and exfiltrate data — know immediately. When GRIT investigators pressed Ransom Busters, the group confirmed access to the exact same dataset the ransomware affiliate possessed. That's not a coincidence. That's the same person.
## The Ecosystem Logic Behind the Scam
To understand why an affiliate would run this play, you need to understand how ransomware-as-a-service actually works. RaaS groups provide infrastructure, malware, and negotiation support. Affiliates do the actual intrusion work and keep a cut — typically 70-80% of whatever ransom gets paid. The RaaS operator takes the rest.
Ransom Busters is running a bypass. Instead of splitting the ransom with the RaaS group through official channels, the affiliate goes directly to the victim with a lower price point. The victim pays less than the full ransom demand. The affiliate pockets the whole amount. The RaaS group gets nothing.
In that narrow sense, this is genuinely adversarial toward the criminal infrastructure — which is why the blog post frames it as the actor "undermining its own business model." But don't mistake that internal conflict for any benefit to victims. Paying Ransom Busters doesn't guarantee data deletion (there's no enforcement mechanism in criminal deals), doesn't necessarily provide working decryption, and hands money directly to the person who just attacked you. You're not getting a better deal. You're getting a second extortion.
## What the $20K to $60K Range Tells Us
The pricing is tactical. Major ransomware groups often demand hundreds of thousands or millions from corporate victims. Ransom Busters is pricing its fake service below the real ransom, making it look like a comparative bargain. It's the same psychology as a scammer offering to recover your stolen card information for "just" $500 — the anchor is whatever larger loss you're already facing.
That pricing window also suggests a target profile: companies large enough to have meaningful data worth stealing but perhaps without the institutional IR relationships or cyber insurance coverage to navigate a seven-figure ransom negotiation. Mid-market companies. Regional healthcare systems. Municipal governments. Exactly the segment that gets hit hardest and has the fewest resources to vet an unsolicited offer.
## Spotting the Fake
GuidePoint laid out the red flags clearly, and they're worth repeating for anyone who might find an email like this in their inbox:
If your organization receives an unsolicited contact claiming knowledge of an active or recent breach — especially before any public disclosure — treat it as evidence of compromise, not help. Report it to law enforcement and your legitimate IR partner immediately.
---
## HackWire Analysis
What's being reported here as a novel scam is actually the latest iteration of a problem that has plagued the ransomware recovery market for years: the blurring of lines between legitimate recovery services and actors with at least one foot in the criminal ecosystem.
In 2019, ProPublica documented how two prominent data recovery firms were secretly paying ransoms and billing clients for "proprietary decryption technology." That was passive complicity. Ransom Busters is something more active and more dangerous: a direct participant in the attack running a parallel racket against victims of the same operation.
What makes this moment significant is the timing relative to how crowded the "ransomware recovery" market has become. The explosion of IR firms, public adjusters, and ransom negotiation specialists over the past five years has created an environment where victims under pressure are primed to accept outside help quickly. Ransom Busters is exploiting exactly that reflex — the instinct to find anyone who can make the problem go away.
The DragonForce and Anubis connections are worth watching. Both groups have shown operational flexibility in recent months, and the affiliate-level defection model this represents — affiliates running side channels that cut out the RaaS operator — could become more common if ransomware economics continue to tighten. Law enforcement pressure, cryptocurrency tracking, and improved corporate defenses have all squeezed margins. Affiliates looking to maximize per-incident take have an obvious incentive to bypass their own operators.
For defenders and IR professionals: the practical implication is that your incident communication protocols now need to account for adversarial contact attempts. Who in your organization can receive and respond to emails claiming to offer recovery help? That person needs to know what Ransom Busters looks like — and needs a clear escalation path that doesn't involve anyone wiring money.
The real asymmetry here: Ransom Busters can credibly demonstrate knowledge of your data because they actually have it. That proof of access is what makes the pitch convincing. Don't mistake evidence of the crime for credentials of the solution.
— HackWire Editorial
---
## Related Coverage