"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research and Intelligence Team (GRIT) warned.
Ransom Busters' pitch and the fee it demands
A self-styled affiliate calling itself Ransom Busters has been observed emailing victim organizations directly, requesting contact with their CEO or IT leadership and offering to delete stolen data from ransomware groups' servers in exchange for payments between $20,000 and $60,000. The actor claims to have discovered vulnerabilities in administrative panels used by ransomware-as-a-service (RaaS) operations and asserts it has been breaking into those servers for more than three years. GuidePoint told The Hacker News it saw this pattern while responding to incidents involving DragonForce, Settra, and Anubis.
Forensic overlaps indicate a single affiliate, not a benevolent third party
GuidePoint's analysis of two incidents where Ransom Busters contacted victims revealed "striking" technical similarities that point to a single operator or small set of operators acting as an affiliate rather than a legitimate rescuer. Overlaps include use of SoftPerfect Network Scanner for internal reconnaissance, s5cmd for exfiltration to cloud storage via AWS, and an RMM (Remotely) tool installed through a PowerShell script. The intrusions also involved creation of a local backdoor account using the password "Numlock!123" and the same attacker-controlled hostname, DESKTOP-BBETH6K.
GuidePoint called the possibility that Ransom Busters is a legitimate organization "extremely unlikely," noting that the behavior would amount to a violation of the U.S. Computer Fraud Abuse Act. Justin Timothy, a Principal Consultant at GRIT, added, "This suggests that the operators were very likely either obfuscating the true origin of their access or they were not operating within the confines of the law," and described the group's explanation for charging victims as "puzzling" — namely, that acting for free would put the group's access to threat-actor infrastructure at risk.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageUNC6671's adversary‑in‑the‑middle extortion and the industrialization of credential theft
The Ransom Busters activity arrives alongside GRIT's disclosure of a sustained adversary-in-the-middle (AitM) campaign by UNC6671 (aka Cordial Spider and O-UNC-045), active since April under multiple extortion brands including Falcon, Helix, Pink, Redact, and BlackFile. GRIT linked more than $8 million in payments to 15 Bitcoin wallets controlled by those five brands, reporting an average extortion demand of $600,000.
UNC6671's operation used as many as 78 victim-targeted phishing subdomains across 76 organizations in 15 industry sectors; GRIT noted 40% of those targets were related to hedge funds, venture capital, private equity, asset management and other financial services. As Okta detailed, UNC6671 operated a custom console called Work Panel that provided role-based access control, integrated target reconnaissance via commercial B2B data APIs, automated infrastructure provisioning, and real-time credential relay management using phishing templates that impersonated identity providers such as Okta and Microsoft 365.
GRIT highlighted UNC6671's separation of duties — callers who know only a phone number, managers who see session queues, admins who control infrastructure — and concluded the model treats callers as "interchangeable commodity labor" paid per capture and deliberately prevented from accessing the product of their work.
Ransomware ecosystem shifts, rising payments, and new actors
GuidePoint's findings fit into a broader, fractured ransomware landscape. Check Point's State of Ransomware Q2 2026 report listed 2,139 organizations on data-leak sites, while the share of the top 10 groups fell from 71% to 57.6% as the number of active groups rose from 71 to 93. CYFIRMA observed that modern ransomware campaigns are increasingly pre-positioned access operations — credential harvesting, reconnaissance, privilege escalation and environment preparation — and that attackers are abusing trusted enterprise infrastructure to blend malicious activity with normal operations.
July 2026 saw 873 claimed victims, up from 722 the previous month; March was the year's peak at 909. The most active claimants in July included The Gentlemen (138), Qilin (133), and CRPx0 (46). GuidePoint and other researchers flagged varied behavior across groups: CRPx0 supports white-label RaaS and a Hacking-as-a-Service program and has used ClickFix commands in fake CAPTCHA pages and a clipper payload to steal cryptocurrency. In a separate incident reviewed by Huntress, an Akira affiliate reportedly rebooted a host into Safe Mode with Networking after initial access through a SonicWall VPN — an evasion that prevented encryption but still enabled credential and file-share exfiltration.
Financial metrics reflect the change: Veeam-owned Coveware reported average ransom payments surged 176% from Q1 ($680,081) to $1,880,612 in Q2 2026, even as the median payment declined 50% to $150,000, a gap driven by a small number of very large payments tied to data-exfiltration extortion, including campaigns by Silent Ransom (aka Luna Moth) against law firms.
What this means for financial services, legal firms, and security teams
- Financial services (hedge funds, VCs, asset managers): UNC6671's targeting of financial-services-related subdomains — roughly 40% of detected targets — underscores the need to monitor phishing subdomains and protect identity-provider flows that attackers impersonate.
- Legal firms and high-value professional services: The spike in high-dollar extortion payments for data exfiltration, and Coveware's attribution of several outsized payments to Silent Ransom, means these firms remain attractive targets where stolen data can command large sums.
- Security teams and incident responders: GRIT's finding that a supposed rescuer can itself be an affiliate emphasizes a hard rule: offers from unknown third parties to delete stolen data should be treated as a hoax. As GuidePoint put it, "Payment to any criminal party offers no guarantee that stolen data will be deleted. There are no 'magic bullets' for remedying data exfiltration..."
Ransom Busters' approach — posing as a rescuer while charging for promised deletions — is both a novel twist on extortion and a reflection of a more fragmented, professionalized criminal ecosystem. The forensic footprints GRIT describes (tools, credentials, a repeated hostname) point to an affiliate exploiting the same infrastructure it claims to abjure. Whether victims will treat that as a last resort or reject it outright, the record is blunt: paying a criminal intermediary offers no guarantee, while attackers continue to innovate across phishing, AitM consoles, and pre-positioned access to maximize leverage.
https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html




