Ransom Busters Claims to Have Breached Ransomware Servers, Demands Up to $60,000 from Victims

0
2

Key Takeaways

  • A ransomware affiliate calling itself Ransom Busters contacts victims offering to delete stolen data for $20,000–$60,000, a tactic that mimics legitimate recovery services but is actually a criminal extortion ploy.
  • Technical analysis shows consistent use of SoftPerfect Network Scanner, s5cmd, a PowerShell‑deployed RMM tool, a local back‑door account (“Numlock!123”), and the attacker‑controlled hostname DESKTOP‑BBETH6K, suggesting a single operator behind multiple incidents.
  • GuidePoint’s GRIT warns that paying any criminal party provides no guarantee of data deletion and that such offers should be treated as hoaxes.
  • The threat actor UNC6671 (aka Cordial Spider) has run a sustained adversary‑in‑the‑middle (AitM) campaign since April 2026, using extortion brands such as Falcon, Helix, Pink, Redact, and BlackFile to net >$8 million across 15 Bitcoin wallets.
  • UNC6671 employs a custom Work Panel console for role‑based access, automated reconnaissance, credential relay, and phishing template management, reflecting a highly industrialized vishing‑driven credential‑theft operation.
  • The ransomware ecosystem is fragmenting: while the top‑10 groups’ share fell from 71% to 57.6% in Q2 2026, the number of active groups rose from 71 to 93, with new entrants like Tengu, CRPx0, Majinahanashi, and others emerging.
  • Modern ransomware campaigns increasingly rely on pre‑positioned access, credential harvesting, and abuse of trusted enterprise infrastructure before encryption.
  • In July 2026, 873 claimed ransomware victims were recorded; the most active groups were The Gentlemen (138), Qilin (133), and CRPx0 (46).
  • CRPx0 deviates from typical RaaS models by offering white‑label campaigns, a 100% profit‑sharing model, and a concurrent Hacking‑as‑a‑Service (HaaS) bundle that includes data breach and network disruption services.
  • Akira remains low‑profile, using defense‑evasion tactics such as rebooting victims into Safe Mode with Networking to disable security tools, though the attempt can backfire while still enabling data exfiltration.
  • Coveware reports that average ransom payments surged 176% Q1→Q2 2026 to $1.88 million, driven by a few “lumpy” high‑value extortions (e.g., Silent Ransom/Luna Moth targeting law firms), while the median payment fell 50% to $150 k, highlighting growing payment disparity.

Ransom Busters: A Deceptive Recovery Offer
GuidePoint’s Research and Intelligence Team (GRIT) identified a ransomware affiliate styling itself Ransom Busters that proactively emails victim organizations claiming it can delete stolen data from ransomware groups’ servers for a fee between $20,000 and $60,000. Unlike legitimate cybersecurity firms that wait for an attack to become public before offering assistance, Ransom Busters reaches out immediately after a breach, presenting itself as a helpful third party. The emails typically request contact with the CEO or IT leadership and assert that the actor has uncovered vulnerabilities in the administrative panels of various ransomware‑as‑a‑service (RaaS) platforms, having infiltrated those servers for over three years.

Contact Method and Claims
In the messages, Ransom Busters states it has located the victim’s exfiltrated data on one of the compromised servers and offers to restore access and erase all backups held by the ransomware group upon payment. The group justifies its fee by arguing that operating without compensation would jeopardize its continued access to the threat actor’s infrastructure—a rationale that GRIT describes as “puzzling” and indicative of a financially motivated criminal rather than a benevolent rescuer.

Technical Fingerprint Across Incidents
Analysis of two separate incidents where Ransom Busters contacted victims revealed striking similarities:

  • SoftPerfect Network Scanner was used for internal network reconnaissance.
  • s5cmd facilitated exfiltration of data to cloud storage via AWS.
  • A PowerShell script installed a remotely administered monitoring and management (RMM) tool.
    Both intrusions created a local back‑door account using the password “Numlock!123” and left behind the attacker‑controlled hostname DESKTOP‑BBETH6K. These overlaps strongly suggest a single operator, likely an affiliate rather than an independent third party, is behind the Ransom Busters persona.

Implications and Warnings from GRIT
Justin Timothy, a Principal Consultant at GRIT, emphasized that criminal actors cannot be trusted and may employ deceptive tactics to solicit additional extortion payments. He warned that payment to any criminal party offers no assurance that stolen data will be deleted and that there are no “magic bullets” for remedying data exfiltration. Consequently, organizations should treat Ransom Busters’ offers as hoaxes and rely on proven incident‑response practices rather than unverified third‑party promises.


UNC6671’s Sustained Extortion Campaign
GuidePoint also disclosed details about UNC6671 (aka Cordial Spider, O‑UNC‑045), a threat actor conducting a prolonged adversary‑in‑the‑middle (AitM) operation since April 2026. Targeting financial services, legal, and other sectors, UNC6671 operates under multiple extortion brands—Falcon, Helix, Pink, Redact, and BlackFile—to conceal its true identity and broaden its reach.

Financial Impact and Targeting Patterns
More than $8 million in payments have been traced to 15 Bitcoin wallets linked to these five brands, with an average extortion amount of roughly $600,000. Researchers identified 78 unique phishing sub‑domains across 76 distinct organizations spanning 15 industry sectors; approximately 40 % of those sub‑domains relate to hedge funds, venture capital, private equity, asset management, and other financial‑services firms, underscoring the actor’s focus on high‑value targets.

Work Panel Console and Operational Structure
UNC6671 leverages a custom console named Work Panel that provides role‑based access control, integrates target reconnaissance via commercial B2B data APIs, automates infrastructure provisioning, and manages real‑time credential relay using phishing templates that mimic identity providers such as Okta and Microsoft 365. GuidePoint describes this as a “meaningful evolution” in the industrialization of vishing‑driven credential theft. The group’s internal hierarchy separates callers (who only know a target’s phone number), managers (who view live session queues but nothing else), and administrators (who own the infrastructure). This compartmentalization treats callers as interchangeable labor, recruited through underground channels and paid per successful credential capture, while deliberately preventing them from accessing the fruits of their own work—an design aimed at mitigating insider risk.


Shifting Ransomware Landscape
The activities of Ransom Busters and UNC6671 illustrate broader trends in the ransomware threat environment. New groups continue to emerge, including Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova. While Tengu and CRPx0 concentrate mainly on U.S. and Turkish entities, Majinahanashi has focused on Switzerland, Italy, Germany, Bulgaria, and India, with its leak site bearing the tagline “DECISION REQUIRES CLARITY.”

Majinahanashi’s Profile
Security researcher Rakesh Krishnan characterizes Majinahanashi as a mid‑tier ransomware family that makes interesting technical choices around network control and I/O prioritization but lacks extremely advanced anti‑analysis or novel cryptographic techniques. Its implementation appears carefully engineered and performance‑aware, combining classic double‑extortion with selective modern tactics, making it a group worth monitoring.

Statistical Trends and Tactical Shifts
According to Check Point’s State of Ransomware Q2 2026 report, 2,139 organizations appeared on data‑leak sites. The share of the top‑10 groups declined from 71% to 57.6%, even as the number of active groups rose from 71 to 93, indicating a more fragmented ecosystem. CYFIRMA observed that modern ransomware campaigns increasingly prioritize pre‑positioned access, focusing on credential harvesting, reconnaissance, privilege escalation, and environment preparation before encryption. Actors abuse trusted enterprise infrastructure—collaboration platforms, legitimate cloud services, signed binaries, and remote administration tools—to blend malicious activity with normal operations.

July 2026 Victim Surge and Leading Groups
In July 2026 alone, 873 claimed ransomware victims were recorded, up from 722 the prior month; the yearly peak remained 909 victims in March 2026. The most active groups that month were The Gentlemen (138 victims), Qilin (133), and CRPx0 (46).

CRPx0’s Atypical Business Model
Initially presumed to be a standard RaaS operation, CRPx0 deviates markedly. It distributes its locker via lures promising OnlyFans accounts but more notably offers white‑label RaaS—providing buyers the resources to run campaigns under their own brand while promising a 100 % profit‑sharing model (buyers keep all revenue). Simultaneously, CRPx0 markets a Hacking‑as‑a‑Service (HaaS) bundle that includes data breach, network compromise, and other disruption services. The group also employs ClickFix commands hidden in fake CAPTCHA pages and uses a clipper payload for cryptocurrency theft, distinguishing it from many peers.

Akira’s Low‑Profile Tactics
Contrastingly, Akira claimed only 22 victims in July 2026 but remains adept at defense evasion. In a recent incident highlighted by Huntress, an Akira affiliate rebooted a compromised host into Safe Mode with Networking to disable security tools after gaining initial access via a SonicWall VPN. The attempt inadvertently crashed the ransomware due to an out‑of‑virtual‑memory failure, yet the attacker had already exfiltrated credentials and file shares, enabling extortion through threatened leaks even without encryption.

Payment Trends and the Silent Ransom Influence
Veeam‑owned Coveware’s Q2 2026 analysis showed the average ransom payment jumped 176 % from Q1’s $680,081 to $1,880,612, while the median payment fell 50 % to $150,000. This widening gap stems from a handful of unusually large, “lumpy” payments tied to extortions involving data exfiltration rather than pure encryption—most notably the Silent Ransom (aka Luna Moth) campaign targeting high‑profile law firms. The data suggest that while many victims pay modest sums, a few high‑value targets drive the average upward, reflecting the attackers’ shift toward stealing and threatening to leak sensitive information.


Conclusion
The convergence of deceptive recovery offers like Ransom Busters, sophisticated AitM operations such as UNC6671’s Work Panel‑driven campaign, and the rapid proliferation of newer ransomware families underscores a threat landscape that is increasingly organized, financially motivated, and technically adept. Organizations must prioritize robust credential protection, vigilant monitoring for anomalous internal reconnaissance, and skepticism toward unsolicited “recovery” offers, relying instead on verified incident‑response procedures and law‑enforcement guidance. As attackers refine pre‑positioned access tactics and exploit legitimate enterprise services, defenses that integrate identity‑centric controls, network segmentation, and continuous threat‑intelligence feeding will be essential to mitigate the evolving risk.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here