RansomHub was a financially motivated ransomware-as-a-service operation active by 2024 and widely tracked as a major criminal extortion group until its apparent shutdown in April 2025. It is also associated with the alias Spoiled Scorpius. The operation used an affiliate model in which partners conducted intrusions and extortion while the core service maintained leak-site infrastructure and, unusually for a ransomware crew, supplied affiliates with offensive tooling including endpoint-security disabling capabilities. RansomHub conducted double extortion, combining data theft with ransomware deployment and public leak-site pressure. The group publicly listed victims, threatened to sell stolen data, and was linked to repeat extortion of organizations previously compromised by other ransomware actors, including cases suggesting affiliate migration from ALPHV/BlackCat into the RansomHub ecosystem. Reporting also indicates overlap between RansomHub victim postings and previously exposed datasets in some cases, showing that at least some extortion activity may have relied on already accessible data rather than exclusively on fresh intrusions. The group’s tradecraft included post-compromise privilege escalation, persistence, credential theft, lateral movement, and defense evasion. RansomHub intrusions have been associated with use of PsExec and NirSoft credential-harvesting utilities, as well as Mimikatz-style credential access patterns seen across the broader ransomware ecosystem. On Linux, campaigns were documented using CVE-2024-1086 for post-compromise privilege escalation and persistence via new systemd services. RansomHub affiliates were also observed deploying PoorTry, also known as BurntCigar, to disable and even wipe critical endpoint detection and response components before encryption. In addition, RansomHub developed and distributed EDRKillShifter to affiliates, reflecting a comparatively centralized approach to anti-EDR tooling. Betruger has also been reported as commonly deployed by RansomHub affiliates. Victimology was broad and opportunistic, with confirmed targeting across healthcare and healthcare-adjacent organizations, government entities, business services, and other enterprise environments. Public reporting ties the group to attacks or extortion affecting organizations in North America, Europe, Latin America, and elsewhere, with the United States appearing prominently in victim reporting. RansomHub was part of the broader post-LockBit and post-ALPHV ransomware reshuffling of 2024-2025, and its decline or retirement was followed by affiliate movement to other operations including Qilin and DragonForce.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransom group joined by a former BlackCat affiliate that attempted a second extortion of UHG using retained stolen data.
Referenced as one of the ransomware operations DevMan previously affiliated with before launching its own RaaS program.
Ransomware group listed among those targeting healthcare organizations in the EMEA region.
Listed only in the actor index/TTP section without substantive discussion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.