Ethical Hacking News
Ransom Busters, a rogue ransomware operator, has been spotted proactively sending emails to victim organizations, claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. This new player has emerged in the ransomware landscape, posing a threat to organizations and individuals worldwide. As the ransomware industry continues to evolve, it is essential to understand the implications of Ransom Busters' activities and to develop strategies for detecting and mitigating these types of attacks.
Ransom Busters, a rogue operator, has been spotted sending emails to victim organizations claiming to delete stolen data from ransomware groups' servers in exchange for a fee. Ransom Busters' modus operandi stands out as anomalous, claiming to have found vulnerabilities in administrative panels maintained by RaaS operations. Their emails request contact with CEO or IT leadership, claiming to have found data stolen from the company, and ask for a payment between $20,000 to $60,000. An analysis of two incidents revealed striking similarities in tools and techniques used, suggesting a single operator behind the activity. The incident highlights the need for organizations to stay vigilant and proactive in protecting themselves against rogue ransomware operators like Ransom Busters.
Ransomware has become a significant threat to organizations and individuals worldwide, with various groups launching attacks to extort money from victims. However, in recent times, a new player has emerged in the ransomware landscape: Ransom Busters. This rogue operator has been spotted proactively sending emails to victim organizations, claiming to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
According to GuidePoint Research and Intelligence Team (GRIT), Ransom Busters' modus operandi stands out as anomalous, as this is not typically how cybersecurity firms approach ransomware victims. Typically, cybersecurity firms reach out to victims after the attack becomes public knowledge, offering consulting or recovery services. However, Ransom Busters claims to have found vulnerabilities in administrative panels maintained by ransomware-as-a-service (RaaS) operations and breaking into the servers for over three years.
In their emails, Ransom Busters requests contact with the CEO or IT leadership of the victim organization, while claiming to have found data stolen from the company on one of the servers they recently accessed. They ask the victim to make a payment that's anywhere between $20,000 and $60,000 to help them regain access to their files and data and delete all backups held by the ransomware group.
An analysis of two different incidents where Ransom Busters contacted victims has uncovered striking similarities, including overlaps in the tools used, such as SoftPerfect Network Scanner for internal reconnaissance, s5cmd for exfiltrating data to cloud storage via AWS, and Remotely remote monitoring and management (RMM) tool, which is installed through a PowerShell script.
Other commonalities involve the creation of a local backdoor account using the password of "Numlock!123" and the detection of the same attacker-controlled hostname, DESKTOP-BBETH6K, across both intrusions. This raises the possibility that a single operator, mostly an affiliate and not a third-party, is behind the activity.
The implications for ransomware victims are clear: criminal actors cannot be trusted and may employ deceptive tactics to encourage even more limited extortion payments. The guidePoint report states that "Payment to any criminal party offers no guarantee that stolen data will be deleted. There are no 'magic bullets' for remedying data exfiltration and 'Ransom Busters' masquerading as beneficent saviors should be treated as a hoax."
This incident highlights the increasingly fragmented ransomware ecosystem, with new groups emerging and evolving their tactics. According to Check Point's State of Ransomware Q2 2026 report, 2,139 organizations were listed on data leak sites. The share of top 10 groups dropped from 71% the previous quarter to 57.6%, even as the number of active groups jumped from 71 to 93, indicating an increasingly complex and dynamic threat landscape.
The rise of rogue ransomware operators like Ransom Busters underscores the need for organizations to stay vigilant and proactive in protecting themselves against these threats. It is also essential for the cybersecurity industry to develop and share more effective strategies for detecting and mitigating these types of attacks.
In this article, we will delve deeper into the world of ransomware and explore the implications of Ransom Busters' activities on the industry and its victims. We will also examine the tactics and strategies used by Ransom Busters and how they compare to other ransomware groups. Finally, we will discuss the potential consequences of this incident and what organizations can do to protect themselves against similar threats in the future.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Rise-of-Rogue-Ransomware-Operators-A-Threat-to-Ransomware-Victims-and-the-Industry-at-Large-ehn.shtml
https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html
Published: Tue Aug 18 14:59:46 2026 by llama3.2 3B Q4_K_M