The Trust Deficit in Cybercrime: When Ransomware Affiliates Cut Out the Middleman

AI-generated image · US National Wire
An analysis of the 'Ransom Busters' scheme reveals a breakdown in the shadow-payment infrastructure of the ransomware-as-a-service economy.
In the world of illicit payments, trust is the only currency that matters. When that trust collapses, the resulting instability doesn't just affect the victims—it disrupts the very payment rails the criminals rely on.
As The Register first reported, researchers at GuidePoint Security have identified an operation calling itself "Ransom Busters" that targets victims of ransomware attacks before those attacks are made public. The outfit offers to delete stolen data and recover encrypted files for a fee ranging from $20,000 to $60,000—a price point significantly lower than the original extortion demands.
On the surface, this looks like a recovery service. In reality, GuidePoint's Research and Intelligence Team (GRIT) assesses with "moderate confidence" that Ransom Busters is actually a ransomware affiliate. Rather than acting as a third-party hunter, this actor is allegedly moonlighting across multiple ransomware-as-a-service (RaaS) operations, using its insider access to steer payments away from its criminal partners and directly into its own pocket.
From a payments perspective, this is a classic case of disintermediation. The affiliate is effectively attempting to undercut the RaaS operators by posing as a benevolent actor. GuidePoint discovered this pattern while investigating attacks linked to three specific groups: DragonForce, Settra, and Anubis.
The forensic evidence cited by The Register underscores the instability of these trust-less transaction layers. GuidePoint found that intrusions involving Ransom Busters shared highly specific fingerprints, including the use of s5cmd for data transfer to AWS cloud storage, SoftPerfect Network Scanner for reconnaissance, and the Remotely remote-management tool via PowerShell. Most tellingly, the attacker used the same hostname, "DESKTOP-BBETH6K," and the same local backdoor password, "Numlock!123," across different environments.
This suggests that the affiliate isn't just sharing tools, but is actively exploiting its position within the RaaS ecosystem to hijack the payment flow. By claiming to have hacked the ransomware gangs to discover stolen data, the affiliate creates a fraudulent narrative to justify a lower price point, thereby incentivizing the victim to bypass the original extortionists.
Ultimately, the Ransom Busters case illustrates that the cybercrime economy is not a monolith of cooperation, but a fragile network of opportunistic actors. As GuidePoint warns, there is no guarantee that paying these supposed rescuers will actually result in the deletion of stolen information. The breakdown of the shadow-payment infrastructure proves that in a system built on extortion, the only thing more volatile than the victim's security is the loyalty of the criminals.

