#StopRansomware: RansomHub Ransomware
ID: ed578b5a-0fb0-586e-b1b8-f92c61e1b06a
STIX ID: report--ed578b5a-0fb0-586e-b1b8-f92c61e1b06a
Feed Name: CISA Cybersecurity Advisories
This joint FBI/CISA/MS-ISAC/HHS advisory describes RansomHub, a ransomware-as-a-service (formerly Cyclops/Knight) active since February 2024 that has impacted at least 210 victims across multiple critical sectors. The report documents RansomHub affiliates’ TTPs — including phishing, exploitation of known vulnerabilities (several CVEs listed), password spraying, credential theft (Mimikatz), lateral movement (RDP, PsExec, Cobalt Strike), data exfiltration methods, and encryption behavior using Curve25519 — and provides extensive IOCs (IPs, URLs, file paths, emails) alongside defensive mitigations and incident response guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
