RansomHouse, also known as Jolly Scorpius and Ransom House, is a financially motivated cybercriminal group active since late 2021. Its operations initially emphasized stealing corporate data and demanding payment to prevent publication or sale, without encrypting victim systems. The group subsequently adopted file-encrypting ransomware, including Mario, and conducts both data-theft extortion and double-extortion attacks. It operates a dedicated leak site to identify victims, publish stolen information, and pressure organizations into negotiations. RansomHouse targets organizations across multiple sectors, including healthcare, information technology, automotive retail, food distribution, and logistics. Its targeting includes organizations in the United States, Japan, and the United Kingdom. Japanese organizations claimed by the group include retailer Askul and food and logistics company Nichirei. The group exploits vulnerabilities to gain access to corporate environments. Observed intrusion techniques include using non-interactive sessions to bypass multifactor authentication, performing DCSync credential theft against domain controllers, and abusing SSH and RDP for lateral movement. RansomHouse intrusions have also involved commercial endpoint-security disabling tools, including DemoKiller, and bring-your-own-vulnerable-driver techniques to impair defenses before ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RansomHouse claims the Namibian Defence Force, Namibia's national military, as a victim. The listing provides the victim domain and discovery date but makes no claim regarding stolen-data volume, data types, ransom demand, deadline, or proof of compromise.
RansomHouse lists PT Indo Tambangraya Megah, an Indonesian coal producer, as a victim, with a discovery date of 2026-10-02. The post provides no stolen-data details, proof of compromise, ransom amount, or deadline.
RansomHouse claims REXT Holdings Co., Ltd., a Tokyo-based private retail and holding company, as a victim. The post provides no data-volume claim, stolen-data description, ransom demand, deadline, or proof-of-compromise sample.
RansomHouse claims California School Employees Association (CSEA), a US school-employee advocacy association, as a victim. The listing provides no claimed data volume, stolen-data description, ransom demand, deadline, attack vector, or proof of compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.