logo

RansomHouse RaaS Service Upgraded with Double Extortion Strategy that Steals and Encrypt Data

ID: e8bbea13-c561-5f3d-af85-d7e0d1d60c27

STIX ID: report--e8bbea13-c561-5f3d-af85-d7e0d1d60c27

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

RansomHouse (Jolly Scorpius) is a ransomware-as-a-service operation that combines data theft and encryption to extort victims; it uses MrAgent for deployment and the Mario encryptor which employs two-stage, sparse chunked encryption and targets VMware ESXi hypervisors to encrypt large numbers of virtual machines. The campaign has affected at least 123 organizations across critical sectors (healthcare, finance, transportation, government) since December 2021, demonstrating high sophistication and significant operational impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.