logo

RansomHub hits 210 victims in just 6 months

ID: ebd7368f-80db-532e-bd10-991e645497ae

STIX ID: report--ebd7368f-80db-532e-bd10-991e645497ae

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-08-30

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security agencies (CISA, FBI, HHS, MS-ISAC) have issued an advisory on RansomHub, a rapidly growing ransomware operation responsible for at least 210 victims since February; the group — staffed by affiliates from former major ransomware gangs — targets a wide range of sectors including critical infrastructure and emergency services. The advisory highlights RansomHub's preference for exploiting recent and historical vulnerabilities (e.g., EternalBlue/CVE-2017-0144, ZeroLogon), use of credential harvesting (Mimikatz), post-exploitation tooling (Cobalt Strike, Metasploit), and varied exfiltration methods (AWS S3, PuTTY), and recommends basic but critical mitigations such as patching, network segmentation, and phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.