Ransomware debris: an analysis of the RansomHub operation
ID: 4bc7623b-6472-5657-bd81-12ad9fa9a5fd
STIX ID: report--4bc7623b-6472-5657-bd81-12ad9fa9a5fd
Feed Name: Group-IB Blog
This report analyzes the RansomHub ransomware-as-a-service operation, describing its multi-OS/multi-architecture encryptor (including ESXi and SFTP capabilities), affiliate panel features (builders, live-chat negotiations, trial decryptors), recruitment and extortion tactics (low-fee model, regulator threats), tooling provided to affiliates (Killer and legitimate AV-killing utilities), targeting patterns (notably healthcare), and recent operational disruption with possible affiliate migration to Qilin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
