We aren't being presented any evidence that they are playing both sides of the table that brazenly. However, I can't see a situation where if the firm were in a position to stop the ransomware globally that they would actually do so.
Maybe an altruistic individual within the company, but not as a directed managerial effort.
Of course it’s much more plausible that they’re just scumbags looking to make an “honest” profit of a criminal act.