Prolific RansomHub Operation Goes Dark
ID: ae047355-1edd-5dfc-ab9e-69e12598f6e9
STIX ID: report--ae047355-1edd-5dfc-ab9e-69e12598f6e9
Feed Name: Dark Reading
RansomHub, a RaaS operation that emerged in early 2024, appears to have gone dark around April 1; researchers report affiliates may be migrating to other Russian-language RaaS groups (e.g., Qilin or DragonForce). The report details RansomHub's multi-platform encryptor (Windows, Linux, ESXi, FreeBSD across x86/x64/ARM), use of GoLang builds and Curve25519 encryption, double extortion tactics including a public data-leak site, and aggressive affiliate guidance (deleting backups, pressuring victims/regulators). The group targeted healthcare, critical infrastructure, finance, and government sectors and offered affiliates favorable terms (low commission, direct victim communication), increasing its operational impact prior to the disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
