RansomHub Ransomware

Description Summary

RansomHub emerged in February 2024 and quickly became one of the most active RaaS operations after the disruption of LockBit and ALPHV. It advertises a higher affiliate cut (90% to affiliates) to attract experienced operators. Researchers assess RansomHub absorbed many former ALPHV affiliates and shares code lineage with the Knight (Cyclops) ransomware.

Threat Actor

RaaS operators recruiting former ALPHV/LockBit affiliates. As of August 2024 CISA reported impact on at least 210 victims.

Technical Indicators

Encryption Extension
.<6-character-random>
Encryption Algorithm
Curve25519 + ChaCha20 / AES-256 (configurable)
Ransom Note Name
README_<6-char>.txt
Targeted Industries
Healthcare, Critical infrastructure, Financial services, Government
First Seen
February 2024
Last Seen
DEFUNCT since 1 April 2025
Geographical Location
Global

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Data Encrypted for Impact (intermittent, configurable)