RansomHouse is a cybercriminal extortion and ransomware group active since late 2021 or early 2022. It is widely known for initially promoting an encryption-less model centered on data theft, public exposure, and direct extortion, while later reporting and victim cases indicate use of cryptographic lockers as well. Known aliases include Jolly Scorpius, Ransom House, and RansomHouse Group. The group operates a leak site to pressure victims by threatening publication of stolen information and has been associated with repeated victim disclosures across the broader extortion ecosystem. RansomHouse has targeted corporate and institutional environments across multiple sectors, including healthcare, logistics and transportation, retail, manufacturing, financial services, and automotive-related businesses. Reported victims include organizations in Japan, the United States, the United Kingdom, and China, and the group has been linked to disruptive incidents affecting supply chains and business operations. Operational reporting associates RansomHouse with vulnerability exploitation for initial access to enterprise networks. Publicly documented intrusion behavior includes exploitation of exposed services and vulnerabilities, abuse of non-interactive sessions to bypass MFA protections, DCSync activity against domain controllers, credential theft from enterprise identity infrastructure, and lateral movement over remote administration channels such as SSH and RDP. The group has also been observed in incidents involving full-domain compromise paths supplied by upstream access brokers, and commercial EDR-killer tooling has been seen during at least one RansomHouse intrusion. RansomHouse is strongly associated with data-theft extortion and leak-site operations. Although it long claimed not to encrypt victim systems, multiple reports indicate the group later adopted ransomware lockers, including use of the Mario ransomware family. Research has linked Mario’s ESXi/Linux locker lineage to Babuk-derived code reuse, indicating that RansomHouse expanded beyond pure exfiltration into virtualization-focused encryption capability. The group has also been discussed alongside other extortion actors such as Karakurt and STORMOUS in analyses of overlapping victimization and possible ecosystem cooperation, though definitive operational relationships are not consistently established. Available reporting includes references describing the group as Russia-linked, but the evidentiary basis in the supplied facts is limited. Its dominant motivation is financial gain through extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group listed among the active groups for the week with claimed victims.
Conducting ransomware and data theft/extortion attacks against companies in Japan, including logistics and retail organizations, and claiming to steal internal data and threaten publication of stolen information.
Named as one of multiple ransomware groups that later claimed victims shortly after the operator established access, supporting the assessment that the operator acts upstream as an initial access broker.
Claimed responsibility for the Nichirei breach, stole data, and posted some of it online as part of a double-extortion ransomware attack.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.