UNC6671: Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

UNC6671: Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

Ransomware Affiliate "Ransom Busters" Offers Dubious Data Deletion for a Fee

A newly identified ransomware affiliate, self-dubbed Ransom Busters, has been proactively emailing victim organizations with an unusual proposition: deleting stolen data from ransomware groups’ servers in exchange for payments ranging from $20,000 to $60,000. The tactic, uncovered by GuidePoint Research and Intelligence Team (GRIT), stands out as an anomalous extortion scheme, as the group reaches out to victims before attacks become public a departure from typical post-breach recovery services.

Modus Operandi and Suspicious Claims

Ransom Busters targets CEOs and IT leadership, claiming to have exploited vulnerabilities in ransomware-as-a-service (RaaS) administrative panels for over three years. The group asserts it discovered victims’ stolen data on compromised servers and offers to restore access and delete backups for a fee. However, GRIT’s analysis suggests the operation is likely illegal, violating the U.S. Computer Fraud and Abuse Act, and may involve an affiliate obfuscating their true access or operating outside legal boundaries.

When questioned about their fee-based assistance, the group provided a contradictory justification: acting without compensation could jeopardize their access to threat actors’ infrastructure.

Technical Overlaps Point to a Single Operator

Incident responses linked to Ransom Busters reveal striking similarities across attacks, including:

  • Tools used: SoftPerfect Network Scanner (reconnaissance), s5cmd (AWS data exfiltration), and Remotely RMM (installed via PowerShell).
  • Backdoor accounts: A local account with the password "Numlock!123" was created in multiple intrusions.
  • Hostname consistency: The same attacker-controlled hostname (DESKTOP-BBETH6K) appeared in separate incidents.

These overlaps suggest a single operator, likely an affiliate rather than a third-party recovery service, is behind the activity. GRIT warns that paying such actors offers no guarantee of data deletion, as criminal groups cannot be trusted.

UNC6671’s Industrialized Extortion Campaign

Separately, GRIT detailed a sustained adversary-in-the-middle (AitM) operation by UNC6671 (aka Cordial Spider or O-UNC-045), targeting financial services, legal, and other sectors since April 2026. Operating under brands like Falcon, Helix, Pink, Redact, and BlackFile, the group has extorted over $8 million across 15 Bitcoin wallets, with an average demand of $600,000.

Key tactics include:

  • 78 phishing subdomains targeting 76 organizations across 15 industries, with 40% focused on hedge funds, venture capital, and asset management.
  • A custom console (Work Panel) enabling role-based access, automated infrastructure provisioning, and real-time credential relay via phishing templates impersonating Okta and Microsoft 365.
  • Industrialized vishing operations, where callers are treated as interchangeable labor, paid per successful credential capture but deliberately blocked from accessing stolen data.

Ransomware Landscape: Fragmentation and Evolution

The ransomware ecosystem continues to diversify, with new groups emerging in recent months, including Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova. While some, like Tengu and CRPx0, focus on U.S. and Turkish targets, others, such as Majinahanashi, prioritize Switzerland, Italy, Germany, Bulgaria, and India.

CRPx0 stands out for its white-label RaaS model, allowing buyers to run campaigns under their own branding with a 100% profit-sharing model. The group also offers Hacking-as-a-Service (HaaS), including data breaches and network compromises, and employs ClickFix commands in fake CAPTCHA pages alongside cryptocurrency-stealing clipper payloads.

Meanwhile, Akira despite claiming only 22 victims in July 2026 continues to refine defense evasion tactics, including rebooting systems into Safe Mode with Networking to disable security tools. In one incident, the tactic backfired when the ransomware failed to execute due to out-of-memory errors, though the attacker had already exfiltrated credentials and file shares.

  • Q2 2026 saw 2,139 organizations listed on data leak sites, with the top 10 groups’ share dropping from 71% to 57.6% as the ecosystem fragments (now 93 active groups, up from 71).
  • July 2026 recorded 873 ransomware victims, up from 722 in June, with The Gentlemen (138), Qilin (133), and CRPx0 (46) leading in activity.
  • Average ransom payments surged 176% in Q2 to $1.88 million, driven by high-value data extortion cases (e.g., Silent Ransom/Luna Moth targeting law firms). However, the median payment fell 50% to $150,000, reflecting a growing gap between lumpy high-dollar extortions and smaller demands.

Modern ransomware campaigns increasingly prioritize pre-positioned access, leveraging credential harvesting, reconnaissance, and privilege escalation before encryption. Groups are also abusing trusted enterprise tools such as collaboration platforms, cloud services, and remote administration software to blend malicious activity with legitimate operations.

Source: https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html

The Cyber Security Hub™ cybersecurity rating report: https://www.rankiteo.com/company/the-cyber-security-hub

"id": "THE1787078222",
"linkid": "the-cyber-security-hub",
"type": "Cyber Attack",
"date": "4/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Finance', 'Legal', 'Investment'],
                        'type': ['Financial Services',
                                 'Legal',
                                 'Hedge Funds',
                                 'Venture Capital',
                                 'Asset Management']}],
 'attack_vector': ['Phishing', 'Exploited RaaS Administrative Panels'],
 'data_breach': {'data_encryption': True,
                 'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': ['High (Personally Identifiable '
                                         'Information, Financial Data)'],
                 'type_of_data_compromised': ['Stolen data from RaaS servers',
                                              'Credentials',
                                              'File shares']},
 'description': 'A newly identified ransomware affiliate, self-dubbed *Ransom '
                'Busters*, has been proactively emailing victim organizations '
                'with an unusual proposition: deleting stolen data from '
                'ransomware groups’ servers in exchange for payments ranging '
                'from $20,000 to $60,000. The group claims to have exploited '
                'vulnerabilities in ransomware-as-a-service (RaaS) '
                'administrative panels and offers to restore access and delete '
                'backups for a fee. However, the operation is likely illegal '
                'and may involve an affiliate obfuscating their true access.',
 'impact': {'data_compromised': ['Stolen data from RaaS servers',
                                 'Credentials and file shares (Akira)'],
            'financial_loss': ['$20,000 to $60,000 (Ransom Busters)',
                               'Over $8 million (UNC6671)'],
            'legal_liabilities': ['Potential violations of U.S. Computer Fraud '
                                  'and Abuse Act']},
 'initial_access_broker': {'backdoors_established': ['Local account with '
                                                     "password 'Numlock!123'",
                                                     'Remotely RMM via '
                                                     'PowerShell'],
                           'entry_point': ['Phishing subdomains (UNC6671)',
                                           'Exploited RaaS panels (Ransom '
                                           'Busters)'],
                           'high_value_targets': ['CEOs',
                                                  'IT Leadership',
                                                  'Financial Services']},
 'lessons_learned': 'Paying ransomware affiliates offers no guarantee of data '
                    'deletion, and criminal groups cannot be trusted. Modern '
                    'ransomware campaigns prioritize pre-positioned access, '
                    'credential harvesting, and abuse of trusted enterprise '
                    'tools.',
 'motivation': ['Financial Gain', 'Data Extortion'],
 'post_incident_analysis': {'corrective_actions': ['Enhanced monitoring and '
                                                   'network segmentation',
                                                   'Regular security audits '
                                                   'and post-incident reviews',
                                                   'Employee training on '
                                                   'phishing and social '
                                                   'engineering'],
                            'root_causes': ['Exploitation of RaaS '
                                            'administrative panels',
                                            'Phishing and credential '
                                            'harvesting',
                                            'Abuse of trusted enterprise '
                                            'tools']},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransom_demanded': ['$20,000 to $60,000 (Ransom Busters)',
                                    '$600,000 (UNC6671 average)'],
                'ransomware_strain': ['Akira',
                                      'CRPx0',
                                      'Tengu',
                                      'Majinahanashi',
                                      'Qilin']},
 'recommendations': ['Avoid paying dubious third-party recovery services.',
                     'Enhance monitoring for phishing and credential '
                     'harvesting.',
                     'Implement network segmentation and adaptive security '
                     'measures.',
                     'Conduct regular post-incident analysis to identify root '
                     'causes and corrective actions.'],
 'references': [{'source': 'GuidePoint Research and Intelligence Team (GRIT)'}],
 'regulatory_compliance': {'regulations_violated': ['U.S. Computer Fraud and '
                                                    'Abuse Act']},
 'response': {'third_party_assistance': 'GuidePoint Research and Intelligence '
                                        'Team (GRIT)'},
 'threat_actor': ['Ransom Busters', 'UNC6671 (Cordial Spider/O-UNC-045)'],
 'title': "Ransomware Affiliate 'Ransom Busters' Offers Dubious Data Deletion "
          'for a Fee',
 'type': 'Ransomware Extortion'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.