A ransomware affiliate calling itself Ransom Busters has been sending emails to victim organizations with a strange offer. They claim they can delete stolen data from ransomware groups' servers for a fee. The price tag: between $20,000 and $60,000.
GuidePoint Research and Intelligence Team detailed the activity in a report shared with The Hacker News. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," the company said.
Let me walk you through the Ransom Busters affiliate extortion scam and what's happening in the ransomware world right now.
Key Points About Ransom Busters
- Ransom Busters claims to delete stolen data for $20,000 to $60,000
- They say they've been breaking into ransomware servers for three years
- They ask victims to contact their CEO or IT leadership
- GuidePoint has responded to multiple incidents involving this actor
- It's likely a single affiliate behind the activity
What's Going On with Ransom Busters?
The Ransom Busters affiliate extortion scam is pretty unusual. A ransomware affiliate contacts victims directly and offers to help them for a price. They claim they found a way into ransomware groups' servers and can delete stolen data.
The emails ask victims to get their CEO or IT leadership involved. The group says they've been breaking into ransomware servers for over three years. They claim they found the victim's stolen data on one of those servers.
The offer sounds like a lifeline. But it's not. GuidePoint said this is almost certainly not a legitimate operation. It's a violation of U.S. law, and there's no guarantee anything will actually be deleted.
When someone asked why they charged for their help, the group gave a weird answer. They said that acting without compensation would put their access to the threat actor's infrastructure at risk. Translation: they're just making stuff up.
"Payment to any criminal party offers no guarantee that stolen data will be deleted," GuidePoint said. "There are no 'magic bullets' for remedying data exfiltration and 'Ransom Busters' masquerading as beneficent saviors should be treated as a hoax."
What the Evidence Shows
GuidePoint looked at two different incidents involving Ransom Busters. They found striking similarities:
- SoftPerfect Network Scanner for internal reconnaissance
- s5cmd for exfiltrating data to AWS cloud storage
- Remotely RMM tool installed via PowerShell
- A local backdoor account with the password "Numlock!123"
- The same attacker-controlled hostname: DESKTOP-BBETH6K
These overlaps suggest it's the same person behind both attacks. Not a third-party helper. A ransomware affiliate running a scam.
UNC6671: The Call Center of Crime
The Ransom Busters affiliate extortion scam isn't the only thing happening. GuidePoint also detailed a group called UNC6671. They've been running adversary-in-the-middle attacks since April.
The Brands They Use:
- Falcon
- Helix
- Pink
- Redact
- BlackFile
Who They Target:
- Financial services
- Legal industry
- Other big organizations
The Numbers:
- More than $8 million in payments made
- Average extortion amount: $600,000
- 78 phishing sub-domains targeting 76 organizations
- 40% of targets are hedge funds, venture capital, and financial services
Work Panel: The Criminal Console
UNC6671 uses a custom console called Work Panel. It's basically a crime-as-a-service platform.
What It Does:
- Role-based access control
- Automated target reconnaissance
- Automated infrastructure provisioning
- Real-time credential relay
- Phishing templates that look like Okta and Microsoft 365
The Separation of Duties:
- The group runs like a call center. There's a deliberate division of labor:
- Callers know only the phone number of their next target
- Managers see the live session queue but nothing else
- Admins own the infrastructure
This design solves a problem for criminals: insider risk. Callers are interchangeable. They're recruited through public channels, paid per successful capture, and prevented from seeing the results of their own work. It's like a factory line for phishing.
The Changing Ransomware Landscape
The ransomware world is getting more crowded. New groups are popping up all the time.
Recent New Groups:
- Tengu
- CRPx0
- Majinahanashi
- Elite Enterprise
- BARADAI
- Aur0ra
- Lalia
- QV Ransomware
- Friends
- Doommageddon
- PicMo
- Orova
The Trends:
- Tengu and CRPx0 focus on the U.S. and Turkey
- Majinahanashi targets Switzerland, Italy, Germany, Bulgaria, and India
- Majinahanashi's tagline: "DECISION REQUIRES CLARITY"
CRPx0: The Weird One
CRPx0 is an unusual ransomware operation. It was initially assumed to be a RaaS group, but there are some odd features.
White-Label Ransomware:
- Buyers can run campaigns under their own name
- 100% profit-sharing model, buyers keep everything
Hacking-as-a-Service:
- They also offer data breach and network compromise services
- Basically, they'll hack anyone for a price
Other Tactics:
- ClickFix commands in fake CAPTCHA pages
- Cryptocurrency theft using a clipper payload
The Numbers Don't Lie
The ransomware ecosystem is fragmenting.
Q2 2026 Stats:
- 2,139 organizations listed on data leak sites
- Top 10 groups dropped from 71% to 57.6% of the market
- Active groups jumped from 71 to 93
- 873 victims in July 2026 (up from 722 in June)
- Highest month: March 2026 with 909 victims
Most Active Groups:
- The Gentlemen: 138 victims
- Qilin: 133 victims
- CRPx0: 46 victims
Ransom Payments Are Going Up
Coveware analyzed Q2 2026 ransomware payments. The numbers tell an interesting story.
- Average ransom payment: $1.88 million (up 176% from Q1)
- Median payment: $150,000 (down 50%)
Why the Gap?
A few huge payments are driving the average up. These are mostly data exfiltration extortions, not traditional encryption attacks.
Who's Driving This?
Silent Ransom (also known as Luna Moth) has been targeting high-profile law firms. These are the kinds of victims who pay big to avoid leaks.
Akira's Safe Mode Fail
Akira ransomware is still around. But they had a recent screw-up.
In one incident highlighted by Huntress, an Akira affiliate tried to boot a victim into Safe Mode with Networking. The goal was to disable security tools.
It backfired. Safe Mode broke the ransomware too. The Akira process hit a memory failure seconds after launching.
But here's the thing: the attacker had already stolen credentials and file shares. Even without encrypting anything, they could still threaten to leak the data.
Conclusion
The Ransom Busters affiliate extortion scam represents a new innovation in the world of ransomware attacks. The criminal uses his affiliation as a third party to help victims with empty promises.
Key Takeaways:
- Ransom Busters is an affiliate but not a helper
- They are charging $20,000-$60,000 for making false promises
- No assurance that stolen data will be deleted
- UNC6671 conducts vishing campaigns against finance and legal sectors
- The average ransomware cost reached $1,880,000 in Q2 of 2026
- CRPx0 provides white-label ransomware and HaaS
The ransomware landscape is getting more crowded and more fragmented. Stay informed. Stay vigilant.
FAQ Section
What is the Ransom Busters affiliate extortion scam?
A ransomware affiliate contacts victims claiming to delete stolen data from ransomware servers for a fee of $20,000 to $60,000. It's a scam. There are no guarantees with payment.
Is Ransom Busters legitimate?
No. It's a criminal actor pretending to be a helper. Don't pay them.
What is UNC6671?
UNC6671 is a group running adversary-in-the-middle attacks targeting financial services and legal sectors. They use a custom console called Work Panel.
What is CRPx0?
CRPx0 is a ransomware group that offers white-label operations and Hacking-as-a-Service. Buyers can run campaigns under their own name.
What are the latest trends in ransomware?
The average ransom paid has risen to $1.88 million in Q2 2026. There are 93 different groups active in the ecosystem. Exfiltration leads to higher ransoms.