A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research and Intelligence Team (GRIT) said in a report shared with The Hacker News. "While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge."
The cybersecurity company said it has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations.
In emails sent to the victims, Ransom Busters is seen requesting contact with their CEO or IT leadership, while claiming to have found vulnerabilities in administrative panels maintained by RaaS groups and breaking into the servers for over three years.
The financially motivated threat actor also claims in their message that they found data stolen from the company on one of the servers they recently accessed and asks them to make a payment that's anywhere between $20,000 and $60,000 to help them regain access to their files and data and delete all backups held by the ransomware group.
GuidePoint said it observed the modus operandi when responding to incidents from threat groups including DragonForce, Settra, and Anubis, adding that the possibility that it could be the work of a legitimate organization is extremely unlikely, as it amounts to a violation of the U.S. Computer Fraud Abuse Act.
"This suggests that the operators were very likely either obfuscating the true origin of their access or they were not operating within the confines of the law," Justin Timothy, a Principal Consultant at GRIT, said. "When pressed on why they charged for their help, the group offered a puzzling explanation: that acting without compensation would put their access to the threat actor's infrastructure at risk."
An analysis of two different incidents where Ransom Busters contacted victims has uncovered "striking" similarities, including overlaps in the tools used -
- SoftPerfect Network Scanner for internal reconnaissance
- s5cmd for exfiltrating data to cloud storage via AWS
- Remotely remote monitoring and management (RMM) tool, which is installed through a PowerShell script
Other commonalities involve the creation of a local backdoor account using the password of "Numlock!123" and the detection of the same attacker-controlled hostname, DESKTOP-BBETH6K, across both intrusions. This raises the possibility that a single operator, mostly an affiliate and not a third-party, is behind the activity.
"The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments," Timothy said. "'Ransom Busters' or, more likely, the ransomware affiliate maintaining this persona, has shown it will betray even its own criminal partners in pursuit of financial gain."
"Payment to any criminal party offers no guarantee that stolen data will be deleted. There are no 'magic bullets' for remedying data exfiltration and 'Ransom Busters' masquerading as beneficent saviors should be treated as a hoax."
UNC6671's Extortion Attacks
The disclosure comes as GuidePoint sheds light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 (aka Cordial Spider and O-UNC-045) targeting financial services, legal, and other industries since April under various extortion brands, such as Falcon, Helix, Pink, Redact, and BlackFile.
"The observed behavior, which mirrors similar SaaS-centric targeting from groups such as Shiny Hunters, reflects a departure from opportunistic ransomware deployment and data extortion towards purposeful targeting of large victim organizations, also known as 'big game hunting,'" GIRT said.
More than $8 million in payments have been made across 15 Bitcoin wallets attributed to the five data extortion brands during the time period. The average extortion amount stood at $600,000.
As many as 78 unique victim-targeted phishing sub-domains have been identified across 76 distinct organizations spanning 15 industry sectors. Of these, 40% are related to hedge funds, venture capital, private equity, asset management, and other financial services firms.
As recently detailed by Okta, UNC6671 operates a custom console called Work Panel that enables role-based access control, integrated target reconnaissance via commercial B2B data APIs, automated infrastructure provisioning, and real-time credential relay management using phishing templates that impersonate identity providers like Okta and Microsoft 365. According to GuidePoint, it represents a "meaningful evolution" in the industrialization of vishing-driven credential theft.
"The separation of duties – callers who know only their next target's phone number, managers who see the live session queue but nothing else, admins who own the infrastructure – is almost certainly a deliberate organizational design decision that solves the insider risk problem inherent in running criminal operations with hired labor," GIRT said.
"Callers are treated as interchangeable commodity labor, recruited through public underground channels, paid per successful capture and deliberately prevented from accessing the product of their own work."
Ransomware Landscape in Flux
The developments dovetail with the continued evolution of the ransomware landscape, with the emergence of new groups like Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova in recent months.
Unlike Tengu and CRPx0, which have heavily focused on entities located in the U.S. and Turkey, Majinahanashi has mostly targeted Switzerland, Italy, Germany, Bulgaria, and India. The data leak site associated with Majinahanashi has the tagline "DECISION REQUIRES CLARITY."
"Majinahanashi is a mid-tier ransomware family with several interesting technical choices (especially network control and I/O prioritization) but does not exhibit extremely advanced anti-analysis or novel cryptography," security researcher Rakesh Krishnan said.
"Majinahanashi's implementation looks more carefully engineered and performance-aware. Its combination of classic double-extortion with selective modern techniques makes it worth monitoring."
According to Check Point's State of Ransomware Q2 2026 report, 2,139 organizations were listed on data leak sites. The share of top 10 groups dropped from 71% the previous quarter to 57.6%, even as the number of active groups jumped from 71 to 93, indicating an increasingly fragmented ecosystem.
"Modern ransomware campaigns are shifting toward pre-positioned access operations, prioritizing credential harvesting, reconnaissance, privilege escalation, and environment preparation to maximize operational success prior to encryption," CYFIRMA noted last month.
"Ransomware groups are increasingly abusing trusted enterprise infrastructure, including collaboration platforms, legitimate cloud services, signed binaries, and remote administration tools, to blend malicious activity with normal enterprise operations."
In the month of July 2026 alone, a total of 873 claimed ransomware victims were recorded, up from 722 the previous month. The highest number of ransomware victims claimed in a single month this year was 909 in March 2026. The most active groups include The Gentlemen, Qilin, and CRPx0, each claiming 138, 133, and 46 victims, respectively.
CRPx0, which was initially assumed to be a RaaS operation, appears to be an aberration, what with the locker previously distributed via lures claiming to offer OnlyFans accounts.
"The most notable one is the group’s insistence on supporting white-label operations. CRPx0 provides RaaS buyers with the resources to manage ransomware campaigns under the buyer's name and markets a 100% profit-sharing model, allowing buyers to keep all profits," Bitdefender said.
"What's also unusual is CRPx0's simultaneous marketing of a Hacking-as-a-Service (HaaS) program. The program includes data breach, network compromise, and other services intended to disrupt businesses."
What's more, the group has employed ClickFix commands embedded in fake CAPTCHA webpages and resorts to cryptocurrency theft using a clipper payload that sets it apart from other ransomware groups.
In contrast stands Akira, which is estimated to have claimed only 22 victims in July 2026. The ransomware group, however, continues to engage in defense evasion tactics to fly under the radar. In one recent incident highlighted by Huntress, an Akira affiliate is said to have rebooted a victim host into Safe Mode with Networking to knock security tools offline after obtaining initial access through a SonicWall VPN.
"In this incident, Safe Mode also broke the ransomware," security researcher James Northey said. "In its stripped-down memory environment, the Akira process tree hit an out-of-virtual-memory failure seconds after launching. While the anti-EDR effort backfired and the ransomware did not deploy, the attacker had already exfiltrated credentials and file shares. Even without encrypting anything, they can still extort the victim by threatening to leak the stolen information."
Veeam-owned Coveware, in its analysis of the threat in Q2 2026, said the average ransom payment surged 176% from Q1 ($680,081) to $1,880,612, while the median payment declined 50% to $150,000.
"This widening gap stems primarily from a handful of unusually high, 'lumpy' payments for extortions involving data exfiltration rather than traditional data encryption," Coveware said. "A key driver behind this spike was the ongoing campaign by Silent Ransom (also known as Luna Moth) against high-profile law firms."






