Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
Intelligence analysis by Llama

Ransom Busters, a ransomware affiliate, is claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. This is an anomalous behavior as cybersecurity firms commonly reach out to ransomware victims after the attack becomes public knowledge.
Imagine you're a company that's been hacked by ransomware. A group called Ransom Busters contacts you, saying they can help you get your data back if you pay them between $20,000 and $60,000. But this is a trick - Ransom Busters is actually a group of hackers who are trying to scam you. They're not really helping you, and they're just trying to make money off of you.
Analysis
Ransom Busters' Claims: A New Twist in Ransomware Tactics
Ransom Busters, a ransomware affiliate, has been spotted proactively sending emails to victim organizations, claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. This behavior is anomalous as cybersecurity firms commonly reach out to ransomware victims after the attack becomes public knowledge.
GuidePoint Research and Intelligence Team (GRIT) has observed this modus operandi in several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations. The financially motivated threat actor claims to have found vulnerabilities in administrative panels maintained by RaaS groups and broken into the servers for over three years.
The cybersecurity company has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple RaaS operations. In emails sent to the victims, Ransom Busters is seen requesting contact with their CEO or IT leadership, while claiming to have found data stolen from the company on one of the servers they recently accessed and asks them to make a payment that's anywhere between $20,000 and $60,000 to help them regain access to their files and data and delete all backups held by the ransomware group.
GuidePoint said it observed the modus operandi when responding to incidents from threat groups including DragonForce, Settra, and Anubis, adding that the possibility that it could be the work of a legitimate organization is extremely unlikely, as it amounts to a violation of the U.S. Computer Fraud Abuse Act.
UNC6671's Extortion Attacks
The disclosure comes as GuidePoint sheds light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 (aka Cordial Spider and O-UNC-045) targeting financial services, legal, and other industries since April under various extortion brands, such as Falcon, Helix, Pink, Redact, and BlackFile.
The observed behavior, which mirrors similar SaaS-centric targeting from groups such as Shiny Hunters, reflects a departure from opportunistic ransomware deployment and data extortion towards purposeful targeting of large victim organizations, also known as 'big game hunting.'
More than $8 million in payments have been made across 15 Bitcoin wallets attributed to the five data extortion brands during the time period. The average extortion amount stood at $600,000. As many as 78 unique victim-targeted phishing sub-domains have been identified across 76 distinct organizations spanning 15 industry sectors. Of these, 40% are related to hedge funds, venture capital, private equity, asset management, and other financial services firms.
Implications for Ransomware Victims
The developments dovetail with the continued evolution of the ransomware landscape, with the emergence of new groups like Tengu , CRPx0 , Maj
Key points
- Ransom Busters, a ransomware affiliate, is claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
- This behavior is anomalous as cybersecurity firms commonly reach out to ransomware victims after the attack becomes public knowledge.
- GuidePoint has observed this modus operandi in several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple RaaS operations.
- The financially motivated threat actor claims to have found vulnerabilities in administrative panels maintained by RaaS groups and broken into the servers for over three years.
- GuidePoint has shed light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 targeting financial services, legal, and other industries since April under various extortion brands.
If Ransom Busters' claims are genuine, it could lead to a decrease in ransomware attacks as victims may be more willing to pay for legitimate help rather than succumbing to extortion. However, the likelihood of this being a legitimate operation is extremely low, and the majority of ransomware victims should remain cautious and not fall for such scams.
The emergence of Ransom Busters and their claims to delete stolen data in exchange for a fee could lead to a new wave of ransomware attacks, as victims may be more willing to pay for what they believe is legitimate help. This could also lead to a decrease in trust between victims and cybersecurity firms, as some may view these claims as a legitimate offer rather than a scam.



