Reputation repair work
The thing about ransomware is, you need a bond of trust between the writer and the victim. That's why they often have first-rate helpdesks to talk people through their extortion experience.
NotPetya has tarred the Petya brand - the install key that the new malware offers is completely random, and so it would not be possible to recover the files even if the email account attached hadn't been shut down. So yeah, it's not surprising that the actual Petya crew want to help clean this up - otherise, no-one will trust them enough to pay the ransom during any future attacks.