Zero Day Room
Live
Threats

Ransomware Affiliate 'Ransom Busters' Claims to Delete Stolen Data for a Fee

A ransomware affiliate, 'Ransom Busters', has been sending emails to victim organizations claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.

A ransomware affiliate, 'Ransom Busters', has been sending emails to victim organizations claiming to delete stolen data...

Ransomware affiliates have been a significant concern for organizations in recent years, and a new development has come to light in the form of 'Ransom Busters', a ransomware affiliate that claims to delete stolen data from ransomware groups' servers in exchange for a fee.

According to a report by GuidePoint Research and Intelligence Team (GRIT), Ransom Busters has been sending emails to victim organizations, offering to help them recover from ransomware attacks. However, this is unusual, as cybersecurity firms typically only offer consulting or recovery services after the attack becomes public knowledge.

The emails sent by Ransom Busters claim that they have found vulnerabilities in administrative panels maintained by ransomware-as-a-service (RaaS) groups and have broken into the servers for over three years. They also claim to have found data stolen from the company on one of the servers they recently accessed and ask the victim to make a payment of between $20,000 and $60,000 to help them regain access to their files and data and delete all backups held by the ransomware group.

GuidePoint said it observed the modus operandi when responding to incidents from threat groups including DragonForce, Settra, and Anubis, adding that the possibility that it could be the work of a legitimate organization is extremely unlikely, as it amounts to a violation of the U.S. Computer Fraud Abuse Act.

The analysis of two different incidents where Ransom Busters contacted victims has uncovered "striking" similarities, including overlaps in the tools used. These include SoftPerfect Network Scanner for internal reconnaissance, s5cmd for exfiltrating data to cloud storage via AWS, and a Remotely remote monitoring and management (RMM) tool, which is installed through a PowerShell script.

Other commonalities involve the creation of a local backdoor account using the password of "Numlock!123" and the detection of the same attacker-controlled hostname, DESKTOP-BBETH6K, across both intrusions. This raises the possibility that a single operator, mostly an affiliate and not a third-party, is behind the activity.

"The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments," Timothy said. "'Ransom Busters' or, more likely, the ransomware affiliate maintaining this persona, has shown it will betray even its own criminal partners in pursuit of financial gain."

"Payment to any criminal party offers no guarantee that stolen data will be deleted. There are no 'magic bullets' for remedying data exfiltration and 'Ransom Busters' masquerading as beneficent saviors should be treated as a hoax."

### Ransomware Landscape in Flux

The emergence of new groups like Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova in recent months has further complicated the ransomware landscape.

Unlike Tengu and CRPx0, which have heavily focused on entities located in the U.S. and Turkey, Majinahanashi has mostly targeted Switzerland, Italy, Germany, Bulgaria, and India. The data leak site associated with Majinahanashi has the tagline "DECISION REQUIRES CLARITY."

"Majinahanashi is a mid-tier ransomware family with several interesting technical choices (especially network control and I/O prioritization) but does not exhibit extremely advanced anti-analysis or novel cryptography," security researcher Rakesh Krishnan said.

"Majinahanashi's implementation looks more carefully engineered and performance-aware. Its combination of classic double-extortion with selective modern techniques makes it worth monitoring."

### UNC6671's Extortion Attacks

The disclosure comes as GuidePoint sheds light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 (aka Cordial Spider and O-UNC-045) targeting financial services, legal, and other industries since April under various extortion brands, such as Falcon, Helix, Pink, Redact, and BlackFile.

"The observed behavior, which mirrors similar SaaS-centric targeting from groups such as Shiny Hunters, reflects a departure from opportunistic ransomware deployment and data extortion towards purposeful targeting of large victim organizations, also known as 'big game hunting,'" GIRT said.

More than $8 million in payments have been made across 15 Bitcoin wallets attributed to the five data extortion brands during the time period. The average extortion amount stood at $600,000.

As many as 78 unique victim-targeted phishing sub-domains have been identified across 76 distinct organizations spanning 15 industry sectors. Of these, 40% are related to hedge funds, venture capital, private equity, asset management, and other financial services firms.

As recently detailed by Okta, UNC6671 operates a custom console called Work Panel that enables role-based access control, integrated target reconnaissance via commercial B2B data APIs, automated infrastructure provisioning, and real-time credential relay management using phishing templates that impersonate identity providers like Okta and Microsoft 365. According to GuidePoint, it represents a "meaningful evolution" in the industrialization of vishing-driven credential theft.

"The separation of duties - callers who know only their next target's phone number, managers who see the live session queue but nothing else, admins who own the infrastructure - is almost certainly a deliberate organizational design decision that solves the insider risk problem inherent in running criminal operations with hired labor," GIRT said.

"Callers are treated as interchangeable commodity labor, recruited through public underground channels, paid per successful capture and deliberately prevented from accessing the product of their own work."

### Ransomware Groups' Tactics Evolving

The developments dovetail with the continued evolution of the ransomware landscape, with the emergence of new groups and tactics.

Modern ransomware campaigns are shifting toward pre-positioned access operations, prioritizing credential harvesting, reconnaissance, privilege escalation, and environment preparation to maximize operational success prior to encryption, according to CYFIRMA.

Ransomware groups are increasingly abusing trusted enterprise infrastructure, including collaboration platforms, legitimate cloud services, signed binaries, and remote administration tools, to blend malicious activity with normal enterprise operations.

In the month of July 2026 alone, a total of 873 claimed ransomware victims were recorded, up from 722 the previous month. The highest number of ransomware victims claimed in a single month this year was 909 in March 2026. The most active groups include The Gentlemen, Qilin, and CRPx0, each claiming 138, 133, and 46 victims, respectively.

CRPx0, which was initially assumed to be a RaaS operation, appears to be an aberration, what with the locker previously distributed via lures claiming to offer OnlyFans accounts.

"The most notable one is the group’s insistence on supporting white-label operations. CRPx0 provides RaaS buyers with the resources to manage ransomware campaigns under the buyer's name and markets a 100% profit-sharing model, allowing buyers to keep all profits," Bitdefender said.

"What's also unusual is CRPx0's simultaneous marketing of a Hacking-as-a-Service (HaaS) program. The program includes data breach, network compromise, and other services intended to disrupt businesses."

In contrast stands Akira, which is estimated to have claimed only 22 victims in July 2026. The ransomware group, however, continues to engage in defense evasion tactics to fly under the radar. In one recent incident highlighted by Huntress, an Akira affiliate is said to have rebooted a victim host in an attempt to avoid detection.

Related coverage

More from Threats