RansomHub ransomware-as-a-service
ID: 5e5ef421-eef5-5a70-8346-d78f71916878
STIX ID: report--5e5ef421-eef5-5a70-8346-d78f71916878
Feed Name: Group-IB Blog
This Group-IB research describes the emergence of RansomHub, a Ransomware-as-a-Service affiliate program launched Feb 2024 that conducts double-extortion attacks across Windows, Linux, and ESXi, self-propagates within networks, exfiltrates large datasets (often >150 GB) to Mega, recruits affiliates (including former Scattered Spider members), leverages purchased domain/RDP accounts for initial access, and employs common dual-use lateral movement tools; the report maps their TTPs to MITRE ATT&CK, provides IOCs and ransom note/file-extension patterns, and offers defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
