Rogue ransomware affiliate poses as recovery firm to steal payments

Executive Summary

A suspected ransomware affiliate is masquerading as a recovery service named "Ransom Busters", contacting victims before their attacks become public. It claims to provide decryption keys and data deletion for a fee, but actually steals payments from victims. The scheme exploits trust in legitimate recovery firms to defraud users.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-19T20:59:58+00:00 - Category: threat-intel

Original Description: A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

"I believe that a simple and unassuming manner of life is best for everyone, best both for the body and the mind."

— Albert Einstein
Source: Bleeping Computer