Ransomware is allang not just about encryption. In a recently reported case, ransomware extortion goes one step further: an affiliate calls (or emails) victims with a promise that the stolen data will be removed from criminal servers—provided there’s an extra payment. The takeaway is clear: you can’t trust criminals, even when they present themselves as saviors.
According to an analysis by the GuidePoint Research and Intelligence Team (GRIT), an actor named Ransom Busters proactively contacts victims after ransomware incidents. The message is to reach out to your CEO or IT leadership because vulnerabilities may have been exploited in administrative panels of ransomware platforms. That leads to a new request for money.
How “ransomware extortion” turns into fake help
In the emails GRIT describes, Ransom Busters positions itself as an external party that could help regain access to files and data. The striking difference from regular security or recovery services is that, in this case, the approach doesn’t appear to wait until an attack becomes publicly known. GRIT calls this behavior directly unusual.
Where classic incident response often starts with triage, containment, and securing evidence, Ransom Busters instead presents itself as a solution that must be paid for quickly. According to the analysis, the requested amounts range from $20,000 to $60,000.
What the messages claim
The actor claims that, for an extended period—more than three years—they had access to servers linked to ransomware-as-a-service (RaaS) operations. The messages also suggest that stolen data is still somewhere on that infrastructure.
The core of the threat and the request remains the same: victims are supposed to pay in order to (1) regain access to their data and (2) have “all backups” supposedly held by the ransomware group removed. In other words, the demand is framed as a final stop for payment.
But GRIT warns: it isn’t realistic to expect a criminal party to actually remove the stolen information neatly. Moreover, the analysis states there are no “magic solutions” that undo data exfiltration.
Why the tactic can feel convincing
The power of this kind of ransomware extortion isn’t only the amount. Timing and context also make the email more believable for busy teams. The message targets high-level decision-makers—CEO or IT leadership—pushing incident response toward a payment mindset faster.
It also helps that the actor claims to have found “vulnerabilities in administrative panels” and used that access to build a foothold. If part of that story is true, it can give the impression that the sender knows something others don’t.
Technical overlaps point to one actor
GRIT analyzed two incidents in which Ransom Busters contacted victims. In both cases, “notable” similarities were found in the tools used and the traces left behind. The analysis mentions:
- SoftPerfect Network Scanner for internal reconnaissance
- s5cmd to exfiltrate data to cloud storage via AWS
- a RMM tool that was allegedly installed via a PowerShell script
The analysis also notes that a local backdoor account was created with the password “Numlock!123”. In addition, the same attacker-controlled hostname—DESKTOP-BBETH6K—appears in both intrusions. That increases the likelihood that it isn’t a random third party, but the same (affiliate) operator.
No trust: paying offers no guarantee
A key theme in the analysis is that even if victims pay, there’s no certainty that stolen data is actually deleted or that backups won’t exist elsewhere. Paying criminals, the report emphasizes, also doesn’t guarantee recovery.
In other words, this approach can pull victims into a cycle. First there is ransomware, then comes “fake help” as the next extortion demand. That causes additional harm: not just financially, but operationally as well (loss of time, misplaced priorities, and possibly further evidence being lost).
The broader trend: targeted, industrial, and human exploitation
This case fits into a changing ransomware landscape. GRIT describes attacks increasingly involving “pre-positioned access”: first access and reconnaissance, and only later (if at all) encryption or further extortion. At the same time, the importance of credential harvesting, privilege escalation, and environment preparation keeps growing.
It also stands out that attackers more often leverage trusted enterprise infrastructure: collaboration tools, legitimate cloud services, signed binaries, and remote administration tools. By abusing common functionality, the behavior looks more like normal work, making detection harder.
Phishing and vishing variants also show up in broader actor descriptions involving UNC6671 (with multiple extortion branding names). A custom console is mentioned that automates roles, target reconnaissance, and credential relay. The overall picture is less improvisation and more industrialization.
What this means for organizations: practical focus areas
If you’re facing ransomware or exfiltration extortion, it’s tempting to look for a quick “way out”—especially when someone offers help. Still, there are concrete steps you can take to reduce risk.
1) Treat “help offers” as potentially harmful
Not every sender is what they claim. Even if a message sounds technically credible, assume the actor is primarily seeking financial gain. Don’t let decision-making depend solely on the contents of emails.
2) Focus on containment and evidence
As soon as an incident is suspected, the goal is to stop further spread and secure evidence. This also helps support later statements about how access was built (for example via administrative panels, remote tools, or cloud routes).
3) Assess whether data was truly exfiltrated
Payment demands are often accompanied by claims about “found data” or “backups.” Use logs and forensic signals to determine what was actually taken and where.
4) Look at previously abused paths
In the discussed case, tool and host overlaps were identified across multiple intrusions. That means you should check internally whether the same techniques have left traces before.
If you want to see how abuse of remote or administrative access can look in practice, this article on
