Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A threat actor calling itself "Ransom Busters" is proactively emailing ransomware victims, claiming to have breached RaaS group servers and offering to delete stolen data for $20,000–$60,000 GuidePoint GRIT analysis reveals striking tool overlaps (SoftPerfect Network Scanner, s5cmd, Remotely RMM) and a shared backdoor account ("Numlock!123") and hostname (DESKTOP-BBETH6K) across incidents, suggesting a single operator rather than a legitimate third party The actor is believed to be a ransomware
Analysis
TL;DR
- A threat actor calling itself "Ransom Busters" is proactively emailing ransomware victims, claiming to have breached RaaS group servers and offering to delete stolen data for $20,000–$60,000
- GuidePoint GRIT analysis reveals striking tool overlaps (SoftPerfect Network Scanner, s5cmd, Remotely RMM) and a shared backdoor account ("Numlock!123") and hostname (DESKTOP-BBETH6K) across incidents, suggesting a single operator rather than a legitimate third party
- The actor is believed to be a ransomware affiliate betraying its own criminal partners for financial gain, with no guarantee that payment results in data deletion
- UNC6671 (Cordial Spider) is running a sustained adversary-in-the-middle operation since April, generating over $8 million across 15 Bitcoin wallets with an average extortion of $600,000
- UNC6671 operates a custom "Work Panel" console enabling role-based access, B2B API reconnaissance, automated infrastructure provisioning, and real-time credential relay via phishing templates impersonating Okta and Microsoft 365
Why It Matters
This incident highlights the growing sophistication and industrialization of cybercrime operations, where threat actors are not only targeting victims directly but also exploiting the post-breach chaos through deceptive intermediary schemes. For AI and cybersecurity practitioners, it underscores the importance of verifying the provenance of unsolicited recovery offers and treating them as potential secondary extortion vectors. The evolution of criminal infrastructure—such as UNC6671's role-separated operational model—demonstrates how threat groups are adopting enterprise-grade organizational structures to mitigate insider risk and scale operations.
Technical Details
- Ransom Busters TTPs: Uses SoftPerfect Network Scanner for internal reconnaissance, s5cmd for data exfiltration to AWS cloud storage, and the Remotely RMM tool installed via PowerShell scripts; creates local backdoor accounts with the password "Numlock!123" and operates from the hostname DESKTOP-BBETH6K
- UNC6671 Work Panel: A custom console providing role-based access control (callers see only target phone numbers, managers see live session queues, admins own infrastructure), integrated B2B data API reconnaissance, automated infrastructure provisioning, and real-time credential relay management using phishing templates impersonating Okta and Microsoft 365 identity providers
- Targeting scope: 78 unique phishing sub-domains across 76 organizations in 15 industry sectors, with 40% targeting financial services (hedge funds, venture capital, private equity, asset management)
- Extortion brands: UNC6671 operates under multiple personas including Falcon, Helix, Pink, Redact, and BlackFile, collecting payments across 15 Bitcoin wallets
- Ransomware landscape: Proliferation of new groups in recent months including Tengu, CRPx0, Majinahanashi, Elite Enterprise, BARADAI, Aur0ra, Lalia, QV Ransomware, Friends, Doommageddon, PicMo, and Orova
Industry Insight
- Organizations should treat unsolicited post-incident recovery offers from unknown parties as high-probability secondary extortion attempts; establish verified communication channels and involve incident response teams before engaging any third party claiming to have breached attacker infrastructure
- The industrialization of criminal operations—evidenced by UNC6671's role-separated Work Panel and commodity labor model—signals that threat groups are adopting enterprise security practices internally, making detection and attribution increasingly critical for defenders
- The shift toward "big game hunting" with purposeful, SaaS-centric targeting (as seen with UNC6671 and Shiny Hunters) suggests defenders should prioritize hardening identity infrastructure, implementing MFA enforcement, and monitoring for adversary-in-the-middle activity rather than relying solely on perimeter defenses
Disclaimer: The above content is generated by AI and is for reference only.