> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
RANSOMHUB
/actor/ransomhub/ · 0 intel reports
RansomHub is a Ransomware-as-a-Service (RaaS) operation that emerged in February 2024 and rapidly became one of the most active ransomware groups globally within just months of launching , an ascent attributed partly to aggressive affiliate recruitment, competitive revenue-sharing terms (affiliates retain 90% of ransom proceeds), and the absorption of experienced operators displaced by law enforcement disruptions of competing platforms including ALPHV/BlackCat and LockBit.
RansomHub's rise correlates directly with the FBI-led disruption of the ALPHV/BlackCat operation in December 2023. Multiple high-profile ALPHV affiliates , including those responsible for the Change Healthcare attack that caused catastrophic disruption to US healthcare payment processing , reportedly migrated to RansomHub following ALPHV's collapse, immediately providing the new platform with experienced operators capable of executing complex enterprise intrusions.
The group has claimed hundreds of victims across critical infrastructure sectors including healthcare, water utilities, financial services, and government agencies. Notable victims include Change Healthcare (via former ALPHV affiliates), Halliburton (a major US oil services company), and multiple government entities globally. CISA issued a formal advisory in August 2024 specifically warning about RansomHub's rapid growth and critical infrastructure targeting.
RansomHub's technical capabilities include multi-platform ransomware payloads targeting Windows, Linux, VMware ESXi, and FreeBSD environments, as well as variants specifically designed to encrypt network-attached storage (NAS) devices and Amazon S3 cloud storage buckets , demonstrating continuous capability development and adaptation to the diverse IT environments encountered within enterprise victim networks.
Tactical Telemetry and Extortion Framework: In confirmed intrusions, RansomHub employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.