Rogue ransomware affiliate poses as recovery firm to steal payments
Executive Summary
A suspected ransomware affiliate is masquerading as a recovery service named "Ransom Busters", contacting victims before their attacks become public. It claims to provide decryption keys and data deletion for a fee, but actually steals payments from victims. The scheme exploits trust in legitimate recovery firms to defraud users.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-19T20:59:58+00:00 - Category: threat-intel
Original Description: A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
"I believe that a simple and unassuming manner of life is best for everyone, best both for the body and the mind."
— Albert Einstein