🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
RANSOMHUB

/actor/ransomhub/  ·  0 intel reports

Year Established
2024
Attribution
Unknown (Eastern European Suspected)
Motivation
Financial
Modus Operandi (MO)
RaaS, aggressive affiliate recruitment, targeting critical infrastructure
Primary Aliases
Ransomhub

RansomHub is a Ransomware-as-a-Service (RaaS) operation that emerged in February 2024 and rapidly became one of the most active ransomware groups globally within just months of launching , an ascent attributed partly to aggressive affiliate recruitment, competitive revenue-sharing terms (affiliates retain 90% of ransom proceeds), and the absorption of experienced operators displaced by law enforcement disruptions of competing platforms including ALPHV/BlackCat and LockBit.

RansomHub's rise correlates directly with the FBI-led disruption of the ALPHV/BlackCat operation in December 2023. Multiple high-profile ALPHV affiliates , including those responsible for the Change Healthcare attack that caused catastrophic disruption to US healthcare payment processing , reportedly migrated to RansomHub following ALPHV's collapse, immediately providing the new platform with experienced operators capable of executing complex enterprise intrusions.

The group has claimed hundreds of victims across critical infrastructure sectors including healthcare, water utilities, financial services, and government agencies. Notable victims include Change Healthcare (via former ALPHV affiliates), Halliburton (a major US oil services company), and multiple government entities globally. CISA issued a formal advisory in August 2024 specifically warning about RansomHub's rapid growth and critical infrastructure targeting.

RansomHub's technical capabilities include multi-platform ransomware payloads targeting Windows, Linux, VMware ESXi, and FreeBSD environments, as well as variants specifically designed to encrypt network-attached storage (NAS) devices and Amazon S3 cloud storage buckets , demonstrating continuous capability development and adaptation to the diverse IT environments encountered within enterprise victim networks.

Tactical Telemetry and Extortion Framework: In confirmed intrusions, RansomHub employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles