Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

August 18, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Organizations previously targeted by RaaS groups
Incident: A threat actor is posing as a recovery service to extort victims of ransomware attacks.
Impact: Financial loss and potential further data exposure through deceptive ‘recovery’ schemes.
Attacker: Ransom Busters
Analysis: Ransom Busters is employing a deceptive social engineering tactic by claiming to have infiltrated RaaS servers to ‘recover’ stolen data for a fee. Technical evidence, including the use of SoftPerfect Network Scanner and a specific local backdoor password, suggests the operator is likely a ransomware affiliate rather than a legitimate entity. This represents a secondary extortion trend where criminals prey on the desperation of existing victims.
Recommendations: Avoid engaging with unauthorized third parties claiming to possess stolen data; Verify all recovery and negotiation services through licensed, reputable cybersecurity firms; Audit local accounts for unauthorized backdoors and rotate credentials following an incident
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *