logo

NoName ransomware gang deploying RansomHub malware in recent attacks

ID: b2a04210-a123-5967-850a-39eb6815b8bf

STIX ID: report--b2a04210-a123-5967-850a-39eb6815b8bf

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

NoName (tracked as CosmicBeetle) is an active ransomware group targeting small and medium businesses using the ScRansom/Spacecolon family and a combination of brute-force access and exploitation of SMB-related CVEs (e.g., CVE-2017-0144, CVE-2020-1472). ESET and other researchers observed ScRansom's partial-encryption and irreversible 'ERASE' modes, a complex AES-CTR/RSA key exchange that can cause decryption failures, attempts to impersonate LockBit via cloned leak sites, and deployment of RansomHub's EDR-killer—leading researchers to assess a likely RansomHub affiliate relationship.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.