← BACK TO FEED
ransomwareextortionUNC6671RaaSthreat intelligence

Meet Ransom Busters: The Ransomware Affiliate Posing as Your Rescuer While Charging $60K for the Privilege

A ransomware affiliate known as **Ransom Busters** is targeting victim organizations with unsolicited emails, claiming to have hacked ransomware groups' servers and offering to delete stolen data in exchange for fees of $20,000–$60,000. Cybersecurity firm GuidePoint found strong technical evidence — including shared tools, identical passwords, and the same attacker hostname across multiple incidents — suggesting the group is itself a ransomware affiliate rather than any legitimate third party, essentially running a secondary extortion scheme against victims already attacked by groups like DragonForce. Experts warn that paying such actors provides no guarantee data will be deleted and should be treated as a scam. The article also highlights the **broader ransomware landscape**, which is growing more fragmented and sophisticated, with 93 active groups recorded in Q2 2026, 2,139 organizations listed on data leak sites, and average ransom payments surging 176% to nearly $1.9 million — driven largely by data exfiltration-focused extortion rather than traditional encryption attacks.

A threat actor operating under the name Ransom Busters has been cold-emailing ransomware victims, claiming it can delete their stolen data from RaaS group servers for fees between $20,000 and $60,000. The pitch: we hacked the hackers, found your files, pay us and we'll make it go away.

GuidePoint's research team spotted the pattern while responding to multiple ransomware incidents and published their findings this week. What made it stand out immediately was the timing. Unlike legitimate cybersecurity firms, which typically approach victims only after an incident becomes public, Ransom Busters was contacting organisations before they'd gone public with anything.

The emails request direct contact with CEOs or IT leadership and claim the sender has been exploiting vulnerabilities in ransomware group admin panels for over three years. It's a bold story. Whether it's true is another matter entirely.

GuidePoint's analysis of two separate incidents linked to Ransom Busters found some telling technical overlaps: SoftPerfect Network Scanner for internal recon, s5cmd for pushing stolen data to AWS, and the same RMM tool installed via PowerShell. Both intrusions also featured a backdoor local account with the password "Numlock!123" and the same attacker-controlled hostname, DESKTOP-BBETH6K. That's not a coincidence. That's a single operator with bad password hygiene.

The working theory is that Ransom Busters is a ransomware affiliate running a sideline extortion operation, targeting the same victims they've already helped compromise through their primary RaaS work. Justin Timothy, Principal Consultant at GuidePoint, noted that when pressed on why they charged for their services, the group offered the genuinely baffling explanation that working for free would somehow endanger their access to the threat actor's infrastructure. Sure.

The takeaway is straightforward: paying criminals doesn't delete your data. There's no mechanism to verify it, no enforcement, and absolutely no reason to trust someone who's already demonstrated they're operating across multiple criminal enterprises simultaneously.

UNC6671: The Industrialised Vishing Operation

Separately, GuidePoint has been tracking UNC6671, also known as Cordial Spider or O-UNC-045, a group running a sustained adversary-in-the-middle operation against financial services, legal firms, and other sectors since April. They operate under at least five extortion brands: Falcon, Helix, Pink, Redact, and BlackFile.

The numbers are not small. Over $8 million in payments across 15 Bitcoin wallets. Average extortion demand sitting at $600,000. Seventy-eight phishing subdomains targeting 76 organisations across 15 industry sectors, with 40% of victims in financial services including hedge funds, private equity, and asset managers.

Okta previously detailed UNC6671's custom tooling, a console called Work Panel that handles role-based access, automated infrastructure provisioning, real-time credential relay, and target reconnaissance pulled from commercial B2B data APIs. It impersonates Okta and Microsoft 365 to harvest credentials via vishing campaigns.

What GuidePoint finds notable is the operational structure. Callers only know their next target's phone number. Managers see the live session queue but nothing else. Admins own the infrastructure. It's a deliberate separation of duties that limits insider risk, each role knows only what it needs to, and workers are recruited through underground channels, paid per successful credential capture, and kept entirely away from the results of their own work. Commodity labour, criminal edition.

The Ransomware Ecosystem Gets Messier

The broader ransomware picture continues its chaotic expansion. New groups including Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova have all emerged recently. Yes, that's a lot of names.

Check Point's Q2 2026 State of Ransomware report counted 2,139 organisations listed on data leak sites. The share claimed by the top ten groups fell from 71% to 57.6%, while active group count jumped from 71 to 93. The ecosystem is fragmenting, which makes it harder to track and, arguably, harder to disrupt.

July 2026 saw 873 claimed victims, up from 722 in June. The busiest single month this year was March with 909. The Gentlemen, Qilin, and CRPx0 topped the charts with 138, 133, and 46 claimed victims respectively.

CRPx0 is worth a second look. Initially thought to be a conventional RaaS operation, it's weirder than that. It offers white-label ransomware services where buyers run campaigns under their own branding and keep all profits. It also simultaneously markets a Hacking-as-a-Service programme covering data breaches and network compromise. On top of that, it uses ClickFix commands embedded in fake CAPTCHA pages and deploys a clipboard hijacker to steal cryptocurrency. Eclectic portfolio.

Akira, by contrast, claimed just 22 victims in July, but remains operationally active and tactically inventive. In one recent incident documented by Huntress, an Akira affiliate rebooted a compromised host into Safe Mode with Networking specifically to disable security tooling. The plan backfired: the stripped-down environment caused the ransomware process to crash with an out-of-virtual-memory error before it could encrypt anything. Unfortunately, the attacker had already exfiltrated credentials and file shares before trying, so the victim still faces extortion. No encryption required.

On the financial side, Coveware's Q2 2026 analysis found the average ransom payment jumped 176% quarter-on-quarter to $1.88 million, while the median dropped 50% to $150,000. The gap reflects a small number of very large payments skewing the average upward, driven largely by Silent Ransom's campaign against high-profile law firms. A handful of enormous payouts, lots of smaller ones, and the mean tells you almost nothing useful.

READ NEXT
Ransomware Crews Have Done Their Homework: It's the IT Manager They WantPaying Ransomware Criminals Doesn't Make Them Go Away. Surprise.Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to Pay