Who Ya Gonna Call? Meet Ransom Busters
A ransomware crew is selling incident response to the companies it just attacked. The audacity is impressive. The packaging is the actually interesting part.
Hello there cyber fanatics!
Every now and then a story comes along that makes me stop what I am doing and just enjoy it for a minute. This is one of those.
Last week the GRIT team at GuidePoint published research on a crew calling itself Ransom Busters. The pitch is beautiful. They email companies that have just been hit by ransomware with some good news: they found a vulnerability in the ransomware group's admin panel, they can delete the stolen data, and they can get the decryption keys back. All for somewhere between $20,000 and $60,000.
Sounds like a bargain. Cheaper than most ransom demands, and you get to feel like the good guys won one for a change.
Here is the problem. GRIT assesses that Ransom Busters are not researchers who found a bug. They are an affiliate working across DragonForce, Settra and Anubis.
So the rescue is being sold by the people who broke in.
Let me get one thing out of the way first
When I first read this I almost wrote it up as a betrayal story. Affiliate robs his bosses, three of them at once, big drama.
That would have been wrong, and if you saw that take somewhere this week, it was wrong there too.
Affiliates are not employees. They are free agents. Working with several RaaS programs at the same time is completely normal, and the good ones go wherever the split is best. There is no contract being broken here and no boss being betrayed. There is no honor among thieves, and there is especially no honor among talented thieves.
So the interesting part of this story is not the disloyalty. It is the costume.
Selling the cure for a virus you invented
Read the pitch again slowly.
They break into your network. They steal your files. They encrypt your systems. And then they come back around the front, knock on the door wearing a different hat, and offer to sell you incident response.
For a fee, they will make the bad thing go away. The bad thing they did.
This is the guy who throws a rock through your window and then rings the bell to ask if you need a glazier. It is a protection racket with a service catalog. And I have to admit there is something almost impressive about the sheer nerve of it.
But here is what actually caught my attention, and it is not the audacity.
It might work better than asking for a ransom.
Think about what happens inside a victim organization. A ransom payment is a ransom payment. It goes to legal. It goes to the board. It goes to the insurer. Somebody has to write down that the company paid a criminal organization, and everyone in the room knows exactly what they are approving and how it will read later.
Now change the label. A $40,000 invoice from a data recovery consultancy is a line item. Companies pay invoices like that every week without anybody's blood pressure changing. Different approver, different paperwork, different conversation, possibly a different disclosure obligation.
I want to be careful here because I have not tested this and I am not a lawyer. But it is worth sitting with the possibility that the costume is not there to soothe the victim's conscience. It might be there to simplify the victim's paperwork. And if that is true, then this is not a joke at all. It is a pricing and packaging decision, and a smart one.
Haven't we seen this before?
Yes. We absolutely have. And I know because I wrote about it.
In May 2022 I published research on a group called RansomHouse. Their entire public identity was built on this exact move. They did not present themselves as extortionists. They presented themselves as a security consultancy that had, unfortunately, been forced to take action.
Here is what I wrote at the time:
RansomHouse is practically forcing "penetration testing services" on organizations that never used their services or rewarded bug bounties, and once they find any vulnerabilities, they fully exploit them to steal as much sensitive data as possible.
And:
Ironically, RansomHouse announced on their Onion site that they are pro-freedom and support the free market, but on the other hand, they punish organizations that choose to not invest in their protection systems.
The whole thing was framed as a favor you did not ask for. So, we ran a scan on you. Here is our report! If you would like the findings, and also the files we took as part of our assessment, just pay our fee. Which follows a red team engagement you never authorized. And the payment is in cryptocurrency. And if you decline, we cannot return your data. And we are having some storage issues, so if you decline we will have to publish it on our site where everyone can see it. Which is on the dark web.
Not sketchy at all.
Four years later, a different crew, a different job title, exactly the same idea. RansomHouse called themselves red teamers. Ransom Busters call themselves incident responders. The costume changed, the trick did not.
And if you want to know how the RansomHouse story ended: in August 2024, CISA and the FBI named them in advisory AA24-241A as one of the ransomware groups taking paid extortion work from Iran-linked state actors. The crew with the higher purpose, who were only doing this to make companies take security seriously, ended up as a subcontractor for a nation state.
They are still going, by the way. Over two hundred victims, still posting this month, and in four years not a single arrest.
How they got caught
Quick note on this, because it is my favorite kind of detail.
Two intrusions, under two different RaaS brands, shared the same backdoor password. Numlock!123. They also shared an attacker machine hostname. DESKTOP-BBETH6K.
That is the whole break. Somebody put two incident reports side by side and noticed the same string turning up twice where it should have turned up once.
No AI. No zero day. No nation state toolchain. Two documents and someone paying attention.
If you are early in this field and you are wondering what threat intelligence actually looks like on a Tuesday afternoon, it looks like that. Read carefully. Write things down properly. Notice when a detail repeats.
So what now?
Ransom Busters will probably change the name and keep going, because there is no reason not to. The GRIT write-up burns the handle and the two indicators, and that is a bad week, not a bad career.
But the packaging idea is the part that spreads. RansomHouse proved in 2022 that the legitimacy costume works, and here it is again in 2026 with a fresh job title. Somebody will run it as breach coach, or as a compliance remediation service, or as an insurance adjuster. It costs nothing to try, and the upside is that a victim who would refuse to pay a ransom might well approve an invoice.
Nothing about this is new. It is a very old con with a new business card, which is more or less how everything in our industry works, unfortunately.
Have fun out there, and go read the GRIT write-up, it is worth your time.