Brown hat hackers have an incentive to create non-functional ransomware, to spread FUD on the legitimate ransomware. If news spreads that some ransomware does not actually decrypt the files after payment, then potential victims would have a stronger incentive to secure their systems, and a weaker incentive to stockpile ransom funds (wt actual f!)
Then, the onus would once again be on the legitimate ransomware developers to prove their ability to do business, and some sort of Ethereum based automated contract might be an ideal tool for that.