logo

RansomHub extortion gang linked to now-defunct Knight ransomware

ID: 035cd733-7a46-50b1-869d-86fe62dd37cb

STIX ID: report--035cd733-7a46-50b1-869d-86fe62dd37cb

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

RansomHub is a prolific ransomware-as-a-service believed to have been derived from the recently defunct Knight ransomware after its source code surfaced; analysts found multiple technical overlaps (both written in Go, Gobfuscate obfuscation, unique string encoding, identical command help, and safe-mode reboot behavior). Since emerging in early 2024, RansomHub has focused on data theft and extortion — publishing stolen files (linked to Change Healthcare) and threatening/leaking data from victims such as Christie’s — indicating active, large-scale criminal operations likely run by actors who acquired Knight’s code and attracted former affiliates of other RaaS groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.