logo

What is RansomHub? Looks like a Knight ransomware reboot

ID: ef83e20d-0a85-5a67-9cca-3d12a98a5a5e

STIX ID: report--ef83e20d-0a85-5a67-9cca-3d12a98a5a5e

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-06-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Symantec links the newly prominent RansomHub ransomware-as-a-service operation to the Knight ransomware codebase and attributes multiple high-profile data thefts (Christie's, Frontier, Change Healthcare) to the group; RansomHub operators commonly exploit CVE-2020-1472 (ZeroLogon) for initial access, use legitimate remote-access tools (Atera, Splashtop) and NetScan for reconnaissance, exfiltrate data and pressure victims to pay, and display significant code and ransom-note overlap with Knight suggesting a rebrand or purchase of source code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.