Description Summary
RansomHub emerged in February 2024 and quickly became one of the most active RaaS operations after the disruption of LockBit and ALPHV. It advertises a higher affiliate cut (90% to affiliates) to attract experienced operators. Researchers assess RansomHub absorbed many former ALPHV affiliates and shares code lineage with the Knight (Cyclops) ransomware.
Threat Actor
RaaS operators recruiting former ALPHV/LockBit affiliates. As of August 2024 CISA reported impact on at least 210 victims.
Technical Indicators
Encryption Extension
.<6-character-random>
Encryption Algorithm
Curve25519 + ChaCha20 / AES-256 (configurable)
Ransom Note Name
README_<6-char>.txt
Targeted Industries
Healthcare, Critical infrastructure, Financial services, Government
First Seen
February 2024
Last Seen
DEFUNCT since 1 April 2025
Geographical Location
Global
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 4 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop | |
| T1486 | Data Encrypted for Impact (intermittent, configurable) |