logo

RansomHub ransomware-as-a-service

ID: 5e5ef421-eef5-5a70-8346-d78f71916878

STIX ID: report--5e5ef421-eef5-5a70-8346-d78f71916878

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2024-08-28

Date Updated: 2026-04-28

...
...

This Group-IB research describes the emergence of RansomHub, a Ransomware-as-a-Service affiliate program launched Feb 2024 that conducts double-extortion attacks across Windows, Linux, and ESXi, self-propagates within networks, exfiltrates large datasets (often >150 GB) to Mega, recruits affiliates (including former Scattered Spider members), leverages purchased domain/RDP accounts for initial access, and employs common dual-use lateral movement tools; the report maps their TTPs to MITRE ATT&CK, provides IOCs and ransom note/file-extension patterns, and offers defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.