Connect with us

Security

Ransom Busters Demands $60,000 from Ransomware Victims after Hacking Servers

Published

on

Ransom Busters Offers to Delete Stolen Data from Ransomware Servers for a Fee

A group known as Ransom Busters has been actively reaching out to organizations affected by ransomware attacks, offering to delete stolen data from ransomware groups’ servers in exchange for a payment ranging from $20,000 to $60,000.

The unusual proactive approach of Ransom Busters sets them apart from typical cybersecurity firms, who usually offer assistance after a ransomware attack becomes public knowledge. The group has been identified as an affiliate involved with multiple ransomware-as-a-service (RaaS) operations.

In their emails to victims, Ransom Busters claim to have discovered vulnerabilities in administrative panels maintained by ransomware groups, allowing them access to servers for over three years. They demand payment to help victims regain access to their files, data, and delete all backups held by the ransomware group.

Despite their claims, cybersecurity experts have noted that Ransom Busters’ activities likely violate U.S. laws, casting doubt on the legitimacy of their operations. The group’s insistence on payment for their services has raised suspicions about their true motives.

Common Tactics and Tools Used by Ransom Busters

An analysis of incidents involving Ransom Busters revealed similarities in their tactics and tools, including the use of:

  • SoftPerfect Network Scanner for internal reconnaissance
  • s5cmd for exfiltrating data to cloud storage via AWS
  • Remotely remote monitoring and management (RMM) tool installed through a PowerShell script

Other shared characteristics include the creation of a local backdoor account with the password “Numlock!123” and the use of the attacker-controlled hostname “DESKTOP-BBETH6K.” These findings suggest that a single operator, likely an affiliate, is behind Ransom Busters’ activities.

Victims of ransomware attacks are warned to be cautious of dealing with criminal actors like Ransom Busters, as there is no guarantee that paying them will result in the deletion of stolen data. The group’s deceptive tactics highlight the risks associated with engaging with malicious actors for data recovery.

UNC6671’s Extortion Campaigns Target Financial Services and Legal Industries

GuidePoint has uncovered an ongoing campaign by UNC6671 targeting financial services, legal, and other industries since April under various extortion brands such as Falcon, Helix, Pink, Redact, and BlackFile. The group has collected over $8 million in payments across 15 Bitcoin wallets, with an average extortion amount of $600,000.

UNC6671’s tactics reflect a shift towards purposeful targeting of large organizations, moving away from opportunistic ransomware attacks. The group’s use of a custom console called Work Panel enables sophisticated reconnaissance and credential theft, representing a significant advancement in vishing-driven attacks.

As the ransomware landscape continues to evolve, new groups like Tengu, CRPx0, and Majinahanashi have emerged, each with their own unique tactics and targets. Majinahanashi, in particular, has targeted countries like Switzerland, Italy, Germany, Bulgaria, and India, using a combination of traditional and modern ransomware techniques.

Check Point’s report on the state of ransomware in Q2 2026 highlights the increasing fragmentation of the ransomware ecosystem, with a growing number of active groups engaging in pre-positioned access operations to maximize their impact.

CRPx0 and Akira: Unusual Ransomware Groups with Distinctive Tactics

CRPx0 stands out for its support of white-label operations, providing resources to RaaS buyers to manage ransomware campaigns under their own brand. The group also offers a Hacking-as-a-Service (HaaS) program, including services for data breaches and network compromises.

On the other hand, Akira has focused on defense evasion tactics, such as rebooting victim hosts into Safe Mode with Networking to disable security tools. Despite a lower victim count compared to other groups, Akira’s methods demonstrate a commitment to evading detection and maximizing their impact.

The ransomware landscape continues to evolve, with average ransom payments increasing significantly in Q2 2026 due to high-profile extortion campaigns targeting law firms. As ransomware groups become more sophisticated in their tactics, organizations must remain vigilant to protect against these evolving threats.

See also  False Flag Ransomware: How MuddyWater Leveraged Microsoft Teams for Credential Theft

Trending