A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a fee ranging from $20,000 to $60,000.

“In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,” GuidePoint Research and Intelligence Team (GRIT) said in a report shared with The Hacker News. “While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge.”

The cybersecurity company said it has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations.

In emails sent to victims, Ransom Busters requests contact with the CEO or IT leadership, while claiming to have found vulnerabilities in administrative panels maintained by RaaS groups and to have been breaking into their servers for over three years.

The financially motivated threat actor also claims in their messages that they found data stolen from the company on one of the servers they recently accessed, and asks for a payment of between $20,000 and $60,000 to help regain access to files and data and delete all backups held by the ransomware group.

GuidePoint said it observed this modus operandi when responding to incidents from threat groups including DragonForce, Settra, and Anubis, adding that the possibility of it being the work of a legitimate organization is extremely unlikely, as it amounts to a violation of the U.S. Computer Fraud and Abuse Act.

“This suggests that the operators were very likely either obfuscating the true origin of their access or they were not operating within the confines of the law,” said Justin Timothy, a Principal Consultant at GRIT. “When pressed on why they charged for their help, the group offered a puzzling explanation: that acting without compensation would put their access to the threat actor’s infrastructure at risk.”

Overlapping Tools and Indicators

An analysis of two different incidents where Ransom Busters contacted victims uncovered “striking” similarities, including overlaps in the tools used:

  • SoftPerfect Network Scanner for internal reconnaissance
  • s5cmd for exfiltrating data to cloud storage via AWS
  • Remotely remote monitoring and management (RMM) tool, installed through a PowerShell script

Other commonalities include the creation of a local backdoor account using the password “Numlock!123” and the detection of the same attacker-controlled hostname, DESKTOP-BBETH6K, across both intrusions. This raises the possibility that a single operator — most likely a ransomware affiliate rather than a genuine third party — is behind the activity.

“The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments,” Timothy said. “‘Ransom Busters’ or, more likely, the ransomware affiliate maintaining this persona, has shown it will betray even its own criminal partners in pursuit of financial gain.”

“Payment to any criminal party offers no guarantee that stolen data will be deleted. There are no ‘magic bullets’ for remedying data exfiltration and ‘Ransom Busters’ masquerading as beneficent saviors should be treated as a hoax.”

UNC6671’s Extortion Attacks

The disclosure comes as GuidePoint sheds light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 (also known as Cordial Spider and O-UNC-045) targeting financial services, legal, and other industries since April under various extortion brands, including Falcon, Helix, Pink, Redact, and BlackFile.

“The observed behavior, which mirrors similar SaaS-centric targeting from groups such as Shiny Hunters, reflects a departure from opportunistic ransomware deployment and data extortion towards purposeful targeting of large victim organizations, also known as ‘big game hunting,’” GRIT said.

More than $8 million in payments have been made across 15 Bitcoin wallets attributed to the five data extortion brands during the observed time period, with the average extortion amount standing at $600,000.

As many as 78 unique victim-targeted phishing sub-domains have been identified across 76 distinct organizations spanning 15 industry sectors. Of these, 40% are related to hedge funds, venture capital, private equity, asset management, and other financial services firms.

As recently detailed by Okta, UNC6671 operates a custom console called Work Panel that enables role-based access control, integrated target reconnaissance via commercial B2B data APIs, automated infrastructure provisioning, and real-time credential relay management using phishing templates that impersonate identity providers like Okta and Microsoft 365. According to GuidePoint, it represents a “meaningful evolution” in the industrialization of vishing-driven credential theft.

“The separation of duties — callers who know only their next target’s phone number, managers who see the live session queue but nothing else, admins who own the infrastructure — is almost certainly a deliberate organizational design decision that solves the insider risk problem inherent in running criminal operations with hired labor,” GRIT said.

“Callers are treated as interchangeable commodity labor, recruited through public underground channels, paid per successful capture and deliberately prevented from accessing the product of their own work.”

Ransomware Landscape in Flux

These developments coincide with continued evolution across the ransomware landscape, with new groups including Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova emerging in recent months.

Unlike Tengu and CRPx0, which have heavily focused on entities in the U.S. and Turkey, Majinahanashi has mostly targeted Switzerland, Italy, Germany, Bulgaria, and India. The data leak site associated with Majinahanashi carries the tagline “DECISION REQUIRES CLARITY.”

“Majinahanashi is a mid-tier ransomware family with several interesting technical choices — especially around network control and I/O prioritization — but does not exhibit extremely advanced anti-analysis or novel cryptography,” said security researcher Rakesh Krishnan.

“Majinahanashi’s implementation looks more carefully engineered and performance-aware. Its combination of classic double-extortion with selective modern techniques makes it worth monitoring.”

According to Check Point’s State of Ransomware Q2 2026 report, 2,139 organizations were listed on data leak sites during the quarter. The share of attacks attributed to the top 10 groups dropped from 71% the previous quarter to 57.6%, even as the number of active groups jumped from 71 to 93, indicating an increasingly fragmented ecosystem.

“Modern ransomware campaigns are shifting toward pre-positioned access operations, prioritizing credential harvesting, reconnaissance, privilege escalation, and environment preparation to maximize operational success prior to encryption,” CYFIRMA noted last month.

“Ransomware groups are increasingly abusing trusted enterprise infrastructure, including collaboration platforms, legitimate cloud services, signed binaries, and remote administration tools, to blend malicious activity with normal enterprise operations.”

In July 2026 alone, a total of 873 claimed ransomware victims were recorded, up from 722 the previous month. The highest single-month total this year was 909 in March 2026. The most active groups included The Gentlemen, Qilin, and CRPx0, claiming 138, 133, and 46 victims respectively — a pattern that underscores the sustained intensity of ransomware activity even as the threat landscape continues to diversify.