Ransom Busters Scams Ransomware Victims by Offering to Delete Stolen Data

A financially motivated threat actor calling itself Ransom Busters has been targeting ransomware victims with an unusual extortion scheme.

The group contacts organizations that have already suffered ransomware attacks and claims it has hacked the infrastructure of ransomware gangs. It then offers to recover stolen data and delete copies held by the original attackers in exchange for payments ranging from $20,000 to $60,000. GuidePoint researchers observed this activity while responding to incidents involving ransomware groups including DragonForce, Settra, and Anubis.

Ransom Busters Claims Access to Ransomware Servers

According to GuidePoint Research and Intelligence Team, Ransom Busters sends emails directly to ransomware victims and asks them to contact their CEO or IT leadership.

The attackers claim they discovered vulnerabilities in administrative panels operated by ransomware-as-a-service groups and have maintained access to their infrastructure for years.

The group then claims to have found the victim's stolen data on the ransomware operators' servers.

For a payment of $20,000 to $60,000, Ransom Busters claims it can help victims regain access to their files and delete stolen data and backups maintained by the ransomware group.

Security researchers consider the offer highly suspicious because legitimate incident response companies generally approach victims after an attack becomes known, while Ransom Busters has contacted organizations during ongoing incidents.

Evidence Points to a Ransomware Affiliate

GuidePoint's investigation uncovered similarities between two separate incidents in which Ransom Busters contacted victims.

Researchers found overlapping tools and infrastructure, including:

  • SoftPerfect Network Scanner for internal reconnaissance
  • s5cmd for transferring stolen data to AWS cloud storage
  • A remote monitoring and management tool installed through PowerShell
  • A local backdoor account using the same password
  • The same attacker controlled hostname, DESKTOP-BBETH6K

These similarities suggest that the same operator may be behind both incidents.

GuidePoint assessed with moderate confidence that Ransom Busters is likely not an independent security organization. Instead, it may be a ransomware affiliate working with multiple RaaS operations and using its existing access to divert ransom negotiations toward itself.

Researchers Warn Victims Not to Pay

GuidePoint warned that victims should not assume that paying Ransom Busters will result in their stolen information being deleted.

There is no reliable way for a victim to verify that criminals have permanently removed every copy of stolen data.

Researchers believe the operation could represent an attempt by a ransomware affiliate to exploit victims a second time after the initial ransomware attack.

UNC6671 Expands Data Extortion Operations

The disclosure comes alongside research into UNC6671, also tracked by some security companies as Cordial Spider.

The group has operated under multiple extortion brands, including BlackFile, Redact, Pink, Helix, and Falcon. Google Threat Intelligence has linked UNC6671 to vishing attacks designed to compromise corporate identity and cloud environments.

UNC6671 typically uses voice phishing to impersonate corporate IT or help desk employees. Victims may be contacted on their personal phones and instructed to complete an urgent security action, such as enrolling a passkey or updating multi factor authentication.

Attackers then direct victims toward phishing infrastructure designed to capture credentials or authenticated sessions.

Financial and Legal Organizations Increasingly Targeted

Recent activity linked to UNC6671 shows a shift toward high value organizations.

Researchers have observed targeting of financial services companies, private equity firms, hedge funds, law firms and other organizations holding sensitive corporate information.

Google has previously documented UNC6671 activity involving Microsoft 365 and Okta environments, where attackers use compromised accounts and adversary in the middle techniques to steal credentials and access cloud data.

Ransomware Ecosystem Continues to Fragment

The latest activity highlights how the ransomware ecosystem is becoming increasingly fragmented.

Instead of relying only on traditional ransomware encryption, threat actors are increasingly focusing on data theft, identity compromise, cloud access and extortion.

This creates additional opportunities for criminals to impersonate security researchers, recovery companies or even other ransomware operators.

For organizations affected by ransomware, security teams should independently verify any third party claiming to have access to stolen data or ransomware infrastructure. Organizations should also preserve forensic evidence, involve trusted incident response professionals and avoid providing additional credentials or sensitive information to unknown parties.