logo

Ransomware debris: an analysis of the RansomHub operation

ID: 4bc7623b-6472-5657-bd81-12ad9fa9a5fd

STIX ID: report--4bc7623b-6472-5657-bd81-12ad9fa9a5fd

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2025-04-30

Date Updated: 2026-04-28

...
...

This report analyzes the RansomHub ransomware-as-a-service operation, describing its multi-OS/multi-architecture encryptor (including ESXi and SFTP capabilities), affiliate panel features (builders, live-chat negotiations, trial decryptors), recruitment and extortion tactics (low-fee model, regulator threats), tooling provided to affiliates (Killer and legitimate AV-killing utilities), targeting patterns (notably healthcare), and recent operational disruption with possible affiliate migration to Qilin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.