Breaking
Cyber CrimeDeveloping Story

When Ransomware Victims Get a Rescue Offer From a Stranger

A ransomware affiliate is contacting victims, offering to delete stolen data for $20,000–$60,000. Experts call it a scam.

··1 hour ago·7 min read
man in black hoodie using macbook
Photo by Azamat E on Unsplash

A ransomware affiliate calling itself “Ransom Busters” has been sending unsolicited emails to victim organizations, claiming it can delete stolen data from other ransomware groups’ servers in exchange for a payment between $20,000 and $60,000. The outreach, detailed by GuidePoint Research and Intelligence Team (GRIT), is an unusual turn in the ransomware landscape: a criminal offering help to another criminal’s victim.

Anomalous Outreach

“In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,” GRIT said in a report shared with The Hacker News. “While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge.”

GRIT said it has responded to several recent ransomware incidents involving the threat actor, who is believed to be an affiliate with employment across multiple ransomware-as-a-service (RaaS) operations. In the emails, Ransom Busters requests contact with the victim’s CEO or IT leadership, claiming to have found vulnerabilities in administrative panels maintained by RaaS groups and to have been breaking into their servers for over three years.

The Offer and the Catch

The financially motivated threat actor claims in their message that they found data stolen from the company on one of the servers they recently accessed, and asks for a payment of $20,000 to $60,000 to help the victim regain access to their files and delete all backups held by the ransomware group. But GRIT says the possibility that this is the work of a legitimate organization is extremely unlikely, as it amounts to a violation of the U.S. Computer Fraud Abuse Act.

“This suggests that the operators were very likely either obfuscating the true origin of their access or they were not operating within the confines of the law,” Justin Timothy, a Principal Consultant at GRIT, said. “When pressed on why they charged for their help, the group offered a puzzling explanation: that acting without compensation would put their access to the threat actor's infrastructure at risk.”

Similar Tools, Same Operator

Analysis of two incidents where Ransom Busters contacted victims has uncovered “striking” similarities, including overlaps in the tools used:

  • SoftPerfect Network Scanner for internal reconnaissance
  • s5cmd for exfiltrating data to cloud storage via AWS
  • Remotely remote monitoring and management (RMM) tool, installed through a PowerShell script

Other commonalities involve the creation of a local backdoor account with the password “Numlock!123” and the detection of the same attacker-controlled hostname, DESKTOP-BBETH6K, across both intrusions. This raises the possibility that a single operator, mostly an affiliate and not a third-party, is behind the activity.

“The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments.”

— Justin Timothy, Principal Consultant at GRIT

Timothy further noted that “Ransom Busters” or, more likely, the ransomware affiliate maintaining this persona, has shown it will betray even its own criminal partners in pursuit of financial gain. He added: “Payment to any criminal party offers no guarantee that stolen data will be deleted. There are no 'magic bullets' for remedying data exfiltration and 'Ransom Busters' masquerading as beneficent saviors should be treated as a hoax.”

Wider Extortion Landscape

The disclosure comes as GuidePoint sheds light on a sustained adversary-in-the-middle (AitM) operation orchestrated by UNC6671 (aka Cordial Spider and O-UNC-045) targeting financial services, legal, and other industries since April under various extortion brands, such as Falcon, Helix, Pink, Redact, and BlackFile. “The observed behavior, which mirrors similar SaaS-centric targeting from groups such as Shiny Hunters, reflects a departure from opportunistic ransomware deployment and data extortion towards purposeful targeting of large victim organizations, also known as 'big game hunting,'” GRIT said.

More than $8 million in payments have been made across 15 Bitcoin wallets attributed to the five data extortion brands during the time period. The average extortion amount stood at $600,000. As many as 78 unique victim-targeted phishing sub-domains have been identified across 76 distinct organizations spanning 15 industry sectors. Of these, 40% are related to hedge funds, venture capital, private equity, asset management, and other financial services firms.

Industrialized Vishing

As recently detailed by Okta, UNC6671 operates a custom console called Work Panel that enables role-based access control, integrated target reconnaissance via commercial B2B data APIs, automated infrastructure provisioning, and real-time credential relay management using phishing templates that impersonate identity providers like Okta and Microsoft 365. According to GuidePoint, it represents a “meaningful evolution” in the industrialization of vishing-driven credential theft.

“The separation of duties – callers who know only their next target's phone number, managers who see the live session queue but nothing else, admins who own the infrastructure – is almost certainly a deliberate organizational design decision that solves the insider risk problem inherent in running criminal operations with hired labor,” GRIT said. “Callers are treated as interchangeable commodity labor, recruited through public underground channels, paid per successful capture and deliberately prevented from accessing the product of their own work.”

Ransomware Landscape in Flux

The developments dovetail with the continued evolution of the ransomware landscape, with the emergence of new groups like Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova in recent months. Unlike Tengu and CRPx0, which have heavily focused on entities located in the U.S. and Turkey, Majinahanashi has mostly targeted Switzerland, Italy, Germany, Bulgaria, and India. The data leak site associated with Majinahanashi has the tagline “DECISION REQUIRES CLARITY.”

Security researcher Rakesh Krishnan said: “Majinahanashi is a mid-tier ransomware family with several interesting technical choices (especially network control and I/O prioritization) but does not exhibit extremely advanced anti-analysis or novel cryptography. Its implementation looks more carefully engineered and performance-aware. Its combination of classic double-extortion with selective modern techniques makes it worth monitoring.”

Shifting Dynamics

According to Check Point’s State of Ransomware Q2 2026 report, 2,139 organizations were listed on data leak sites. The share of top 10 groups dropped from 71% the previous quarter to 57.6%, even as the number of active groups jumped from 71 to 93, indicating an increasingly fragmented ecosystem.

“Modern ransomware campaigns are shifting toward pre-positioned access operations, prioritizing credential harvesting, reconnaissance, privilege escalation, and environment preparation to maximize operational success prior to encryption,” CYFIRMA noted last month. “Ransomware groups are increasingly abusing trusted enterprise infrastructure, including collaboration platforms, legitimate cloud services, signed binaries, and remote administration tools, to blend malicious activity with normal enterprise operations.”

In the month of July 2026 alone, a total of 873 claimed ransomware victims were recorded, up from 722 the previous month. The highest number of ransomware victims claimed in a single month this year was 909 in March 2026. The most active groups include The Gentlemen, Qilin, and CRPx0, each claiming 138, 133, and 46 victims, respectively.

CRPx0's Unusual Model

CRPx0, which was initially assumed to be a RaaS operation, appears to be an aberration, what with the locker previously distributed via lures claiming to offer OnlyFans accounts. “The most notable one is the group’s insistence on supporting white-label operations. CRPx0 provides RaaS buyers with the resources to manage ransomware campaigns under the buyer's name and markets a 100% profit-sharing model, allowing buyers to keep all profits,” Bitdefender said. “What's also unusual is CRPx0's simultaneous marketing of a Hacking-as-a-Service (HaaS) program. The program includes data breach, network compromise, and other services intended to disrupt businesses.”

What's more, the group has employed ClickFix commands embedded in fake CAPTCHA webpages and resorts to cryptocurrency theft using a clipper payload that sets it apart from other ransomware groups.

Akira's Stealth and Odd Failures

In contrast stands Akira, which is estimated to have claimed only 22 victims in July 2026. The ransomware group, however, continues to engage in defense evasion tactics to fly under the radar. In one recent incident highlighted by Huntress, an Akira affiliate is said to have rebooted a victim host into Safe Mode with Networking to knock security tools offline after obtaining initial access through a SonicWall VPN.

“In this incident, Safe Mode also broke the ransomware,” security researcher James Northey said. “In its stripped-down memory environment, the Akira process tree hit an out-of-virtual-memory failure seconds after launching. While the anti-EDR effort backfired and the ransomware did not deploy, the attacker had already exfiltrated credentials and file shares. Even without encrypting anything, they can still extort the victim by threatening to leak the stolen information.”

Payment Trends

Veeam-owned Coveware, in its analysis of the threat in Q2 2026, said the average ransom payment surged 176% from Q1 ($680,081) to $1,880,612, while the median payment declined 50% to $150,000. “This widening gap stems primarily from a handful of unusually high, 'lumpy' payments for extortions involving data exfiltration rather than traditional data encryption,” Coveware said. “A key driver behind this spike was the ongoing campaign by Silent Ransom (also known as Luna Moth) against high-profile law firms.”

Why It Matters

The Ransom Busters scheme is a stark reminder that the ransomware ecosystem is not a monolith – it is a marketplace of shifting alliances and betrayals. For victims, the offer of help from a self-proclaimed “busting” service is a trap: paying such an actor provides no guarantee of data deletion, and it may simply line the pockets of the same criminal networks they are trying to escape. As the number of active ransomware groups grows and tactics diversify, organizations must treat unsolicited “rescue” offers with the same skepticism as the initial attack. The only reliable defense remains robust backups, incident response planning, and a firm policy against engaging with any party demanding payment – whether they claim to be the attacker or the savior.

#ransomware#extortion#ransom-busters#guidepoint#vishing#cybercrime

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories