logo

RansomHub Targets Patchable Bugs in Microsoft Active Directory and Netlogon

ID: dac15a6d-5458-5db3-a554-33bb3141d5d4

STIX ID: report--dac15a6d-5458-5db3-a554-33bb3141d5d4

Feed Name: Halcyon Blog

Threat Score
82/100

Date Published: 2025-03-17

Date Updated: 2026-04-28

...
...

RansomHub, an active RaaS platform emerging in 2024, leverages unpatched vulnerabilities (e.g., ZeroLogon, noPac), brute-force attacks, and default/backup accounts to gain domain-level access; they perform credential theft, lateral movement, EDR disablement, data exfiltration, and encryption using modern crypto (Curve25519/ChaCha20/AES) while operating a lucrative affiliate model and conducting double-extortion against high-value targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.