RansomHub Draws in Affiliates with Multi-OS Capability and High Commission Rates
ID: d500876f-f51c-59bd-b312-1b8b290a15eb
STIX ID: report--d500876f-f51c-59bd-b312-1b8b290a15eb
Feed Name: Recorded Future Blog
**RansomHub RaaS emerges as a multi‑OS ransomware threat** — first advertised in February 2024, RansomHub offers affiliates a high 90% commission and delivers Go and C++ malware targeting Windows, Linux, and ESXi; affiliates have claimed 45 victims across 18 countries and have abused misconfigured Amazon S3/cloud backups to extort both primary victims and backup providers. The report notes code overlaps with ALPHV (BlackCat) and Knight Ransomware, provides YARA/Sigma detections and command-line IOCs, and recommends network segmentation, EDR/SIEM, least‑privilege, patching, and offline/backed‑up recovery to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
