Imagine your company has just been hit by ransomware. The incident is still private, the attackers have stolen data, and the outside world does not even know you were attacked.
Then someone else contacts you offering to help.
The supposed recovery service claims it hacked the ransomware gang, found your stolen files on the criminals’ servers, and gained access to encryption keys that could help restore your systems. For $20,000 to $60,000, it offers to delete the stolen data and help with recovery.
Security researchers now believe the service is actually a ransomware affiliate trying to collect a second payment while cutting its own criminal partners out of the deal.
The unusual scheme was uncovered by GuidePoint Security’s Research and Intelligence Team, which encountered the operation while responding to several recent ransomware incidents. The researchers assess with moderate confidence that a single affiliate working across multiple ransomware as a service operations is behind the activity.
If that assessment is correct, victims are effectively being approached twice over the same intrusion, first through the ransomware operation and then by an affiliate pretending to offer a way out.
The timing immediately raised questions
The biggest warning sign was that the supposed recovery service knew about ransomware attacks before they were public.
Several victims received unsolicited emails requesting contact with their CEO or IT leadership. The sender claimed to represent a project that had spent years infiltrating criminal infrastructure and had discovered the victim’s stolen data while accessing ransomware servers.
The actor claimed it had found vulnerabilities in administrative systems used by several ransomware operations, supposedly giving it access to stolen files and encryption keys.
It then offered to delete the victim’s data from the ransomware gang’s servers for between $20,000 and $60,000.
But that created an obvious question: if the ransomware attack had not been publicly disclosed, how did an unrelated recovery service already know exactly which company had been compromised?
The activity surfaced during investigations involving DragonForce, Settra, and Anubis ransomware operations. When challenged, the purported recovery service was able to demonstrate access to the exact same dataset held by the ransomware affiliate involved in the attack.
Forensics connected separate ransomware attacks
The strongest evidence came from inside the victims’ networks.
Incident responders examined 2 environments where the purported recovery service later contacted victims and found striking similarities between the original ransomware intrusions.
Both attackers used the same combination of tools for internal reconnaissance, data exfiltration, and remote access. Investigators also identified matching persistence behavior and the same attacker controlled hostname across both incidents.
The intruders had even created local backdoor accounts using the same password.
Ransomware affiliates frequently reuse tools and techniques, so any one of those similarities would not necessarily prove that the same operator was responsible. Finding the same combination across incidents associated with multiple ransomware programs provided a much stronger connection.
Based on those overlaps and the actor’s knowledge of nonpublic attacks, researchers assess that the recovery service is actually a single ransomware affiliate operating across several ransomware programs.
The affiliate may be cutting out its own partners
The scheme makes more sense when viewed through the ransomware as a service business model.
Many ransomware operations provide malware and criminal infrastructure while affiliates carry out the actual intrusions. When a victim pays, the proceeds are typically divided between the affiliate and the ransomware operators.
A rogue affiliate can potentially make more money by going directly to the victim.
Instead of relying solely on the original ransom negotiation, the affiliate can present itself as an independent recovery service and offer what appears to be a cheaper solution. A company already facing a much larger ransom demand could see a $20,000 to $60,000 offer to delete its data as an attractive alternative.
That would also allow the affiliate to potentially keep the payment instead of sharing it with the ransomware operation.
There is no reliable way for a victim to know whether the stolen information would actually disappear.
The ransomware operators could retain another copy. Other criminals involved in the intrusion could have downloaded the data. The affiliate itself could keep a copy for future extortion.
Even if the actor genuinely deleted one set of stolen files, the victim would have little way to verify that every copy was gone.
Victims are being sold the solution to their own attack
The tactic adds another complication to ransomware response.
Companies routinely receive offers from security vendors after a major cyberattack becomes public. Receiving a message from someone who already knows details of a ransomware incident that has never been disclosed is very different.
That knowledge may indicate that the sender obtained information directly from the intrusion or from someone involved in it.
The purported recovery service also claimed it had illegally accessed ransomware infrastructure in order to retrieve data and encryption keys. Even if that explanation were true, unauthorized access to criminal infrastructure would raise significant legal questions and would hardly resemble the behavior of a conventional incident response company.
Researchers have not identified evidence that any victim successfully paid the operation.
Organizations receiving similar messages should preserve the communications and share them with their incident response team and appropriate law enforcement authorities. Claims involving nonpublic knowledge of an attack, possession of stolen files, or access to ransomware encryption keys should be treated as potential evidence connected to the original intrusion.
The scheme shows how many opportunities criminals now have to monetize a single ransomware attack. Encryption can generate one demand. Stolen data can create another. Leak threats add more pressure. Now, a rogue affiliate may be able to approach the same victim again while pretending to be the company that can make the problem disappear.
For a victim in the middle of a ransomware crisis, the offer might initially look like an unexpected lifeline. The evidence suggests it could simply be another stage of the extortion.











