logo

#StopRansomware: RansomHub Ransomware

ID: ed578b5a-0fb0-586e-b1b8-f92c61e1b06a

STIX ID: report--ed578b5a-0fb0-586e-b1b8-f92c61e1b06a

Feed Name: CISA Cybersecurity Advisories

Threat Score
80/100

Date Published: 2024-08-29

Date Updated: 2026-04-19

Author: CISA

...
...

This joint FBI/CISA/MS-ISAC/HHS advisory describes RansomHub, a ransomware-as-a-service (formerly Cyclops/Knight) active since February 2024 that has impacted at least 210 victims across multiple critical sectors. The report documents RansomHub affiliates’ TTPs — including phishing, exploitation of known vulnerabilities (several CVEs listed), password spraying, credential theft (Mimikatz), lateral movement (RDP, PsExec, Cobalt Strike), data exfiltration methods, and encryption behavior using Curve25519 — and provides extensive IOCs (IPs, URLs, file paths, emails) alongside defensive mitigations and incident response guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.