**The Rise of “Ransom Busters”: A New Twist in Ransomware Extortion**
In a disturbing new trend observed in the cybersecurity landscape, a ransomware affiliate operating under the banner “Ransom Busters” has been identified proactively reaching out to victim organizations. Unlike typical post-attack negotiations, this threat actor claims the ability to delete stolen data from ransomware group servers in exchange for a fee ranging from $20,000 to $60,000.
According to a report by GuidePoint Research and Intelligence Team (GRIT), this approach is highly anomalous. While cybersecurity firms sometimes offer remediation services after a public breach, this third-party intervention occurs before the attack is public knowledge, immediately raising red flags. The cybersecurity company confirmed it has interacted with this actor in recent incidents involving multiple ransomware families, including DragonForce, Settra, and Anubis.
The emails sent by Ransom Busters request contact with the victim’s CEO or IT leadership. The actor claims to have exploited vulnerabilities in administrative panels controlled by Ransomware-as-a-Service (RaaS) groups, asserting they have maintained unauthorized access for over three years. Their message is clear: they have stolen data and will provide proof, demanding payment to regain access and delete the backups held by the primary ransomware group.
GuidePoint’s analysts concluded the likelihood of this being a legitimate organization is “extremely unlikely,” as it constitutes a direct violation of the U.S. Computer Fraud and Abuse Act. “This suggests that the operators were very likely either obfuscating the true origin of their access or they were not operating within the confines of the law,” noted Justin Timothy, a Principal Consultant at GRIT.
A deep dive into two specific incidents revealed significant operational overlaps. The threat actor utilized a consistent toolkit, including:
* **SoftPerfect Network Scanner** for internal network mapping.
* **s5cmd** for exfiltrating data to cloud storage via AWS.
* A Remote Monitoring and Management (RMM) tool deployed via a PowerShell script.
Other forensic markers pointed to a shared methodology, including the creation of a local backdoor account with the password “Numlock!123” and the use of the same attacker-controlled hostname, **DESKTOP-BBETH6K**, across separate intrusions. These findings strongly suggest a single operator working across multiple ransomware affiliate programs rather than disparate groups.
“The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments,” Timothy warned. He emphasized that “Ransom Busters” or its controller has demonstrated a willingness to betray even its own criminal partners for financial gain.
Crucially, the research underscores that paying a criminal party offers no guarantee that stolen data will be deleted. GRIT urges organizations to treat such offers as a hoax, noting there are no “magic bullets” for remediating data exfiltration.
### An Evolving and Fragmented Ecosystem
This development occurs within a rapidly shifting ransomware ecosystem. GuidePoint highlighted the activity of UNC6671 (also known as Cordial Spider), which has been conducting sophisticated, sustained “adversary-in-the-middle” (AitM) attacks against financial services, legal, and other industries since April. These attacks utilize extortion brands like Falcon, Helix, Pink, Redact, and BlackFile.
The scale of this operation is significant. Over 78 unique phishing sub-domains have been identified targeting 76 organizations across 15 sectors, with 40% of the focus on financial services. This has resulted in over $8 million in payments across five distinct extortion brands, with an average ransom of $600,000.
The infrastructure used by UNC6671 represents a “meaningful evolution” in criminal tactics. Utilizing a custom console called Work Panel, the group employs role-based access control, commercial B2B data APIs for target reconnaissance, automated infrastructure provisioning, and real-time credential relay management through phishing templates that impersonate identity providers like Okta and Microsoft 365. This “separation of duties”—where callers are deliberately isolated from the infrastructure and paid per successful breach—is a strategic move to mitigate insider risk.
The broader ransomware landscape is also becoming more dynamic, with new groups emerging frequently. While some, like CRPx0, have focused heavily on U.S. and Turkish targets, others like Majinahanashi have targeted Switzerland, Italy, Germany, Bulgaria, and India. Analysis suggests Majinahanashi represents a technically sophisticated, mid-tier family worth monitoring due to its engineered approach to network control and I/O prioritization, blending classic double-extortion with modern techniques.
This trend is reflected in broader statistics. According to Check Point’s State of Ransomware Q2 2026 report, the number of active ransomware groups jumped from 71 to 93, leading to a fragmented ecosystem where the top 10 groups’ share of attacks dropped from 71% to 57.6%. The volume of claimed victims also rose, with 873 reported in July 2026 alone.
### FAQs
**Q: What is “Ransom Busters”?**
A: “Ransom Busters” is the name used by a ransomware affiliate who has been contacting organizations directly after a ransomware attack. They claim to have stolen data and offer to delete it from the ransomware group’s servers in exchange for a payment, typically between $20,000 and $60,000.
**Q: Is it safe to pay the “Ransom Busters” demand?**
A: No. Cybersecurity experts strongly advise against paying any ransom. Payment offers no guarantee that data will be deleted, and it funds criminal activity. Furthermore, this specific offer is viewed as a deceptive tactic, likely from the same ransomware affiliate trying to extort additional funds.
**Q: What tools did the “Ransom Busters” actor use?**
A: The actor utilized a consistent set of tools, including SoftPerfect Network Scanner for reconnaissance, s5cmd for data exfiltration to AWS, and a Remote Monitoring and Management (RMM) tool deployed via PowerShell.
**Q: What is the “Work Panel” used by UNC6671?**
A: The Work Panel is a custom console used by the threat actor UNC6671. It allows for sophisticated campaign management, including role-based access control, target reconnaissance using commercial data APIs, automated infrastructure setup, and phishing template management.
**Q: Why is the ransomware landscape described as being “in flux”?**
A: The landscape is in flux due to the constant emergence of new ransomware groups with varying tactics, targets, and levels of sophistication. This, combined with the increasing use of legitimate enterprise tools for malicious purposes and a shift towards highly targeted “big game hunting,” shows the tactics of ransomware operations are continuously evolving.
### Conclusion
The emergence of the “Ransom Busters” persona is a stark reminder of the evolving sophistication and deceitfulness of modern ransomware gangs. Rather than simply encrypting data and demanding a ransom, these actors are engaging in multi-layered extortion schemes, attempting to exploit victims’ desperation and trust. The evidence strongly suggests these are not benevolent third parties but rather the same criminal affiliates responsible for the initial breach, looking to maximize their profit at the victim’s expense. Organizations must remain vigilant, understand that criminals cannot be trusted, and prioritize robust defensive and backup strategies over any illusion of a negotiated settlement with a threat actor.



