RansomHub, also tracked as Spoiled Scorpius, is a financially motivated ransomware-as-a-service operation that emerged in February 2024. Its core operators develop ransomware and maintain extortion infrastructure, while affiliates compromise victims, steal data, and deploy encryption payloads. Its affiliate-first payment model allocates 90% of ransom proceeds to affiliates and 10% to the operators. The operation recruited affiliates from disrupted ransomware groups, including ALPHV/BlackCat, and rapidly became a prominent ransomware threat during 2024. RansomHub targets organizations internationally, particularly in the United States, with additional targeting in the United Kingdom, Brazil, Italy, Germany, and Spain. Affected sectors include manufacturing, healthcare, professional and technical services, construction, retail, finance, technology, and government. It combines encryption with threats to publish stolen information on a dedicated leak site. RansomHub also pursued data-theft extortion involving Change Healthcare after the earlier ALPHV/BlackCat incident and claimed an attack on Christie’s auction house. Affiliates obtain initial access through phishing, password spraying, and exploitation of known vulnerabilities, including Zerologon (CVE-2020-1472) and flaws in internet-facing enterprise products. Subsequent activity includes network scanning, credential dumping with Mimikatz, privilege escalation, account creation or reactivation, and lateral movement using RDP, PsExec, Cobalt Strike, Metasploit, and legitimate remote-management tools. Affiliates independently select exfiltration mechanisms, including Rclone, WinSCP, cloud storage, and HTTP transfers. RansomHub-associated actors have used EDRKillShifter to deploy vulnerable drivers and terminate endpoint-security processes before ransomware execution. RansomHub ransomware supports Windows, Linux, and VMware ESXi environments and shares substantial code and operational features with Knight ransomware, formerly known as Cyclops; this technical relationship does not establish continuity between their operators. RansomHub’s leak and victim-communication infrastructure went offline in April 2025. The cause of the disruption and whether the operational halt was permanent remain unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
CVEs exploited by RansomHub: Netlogon Remote Protocol (CVE-2020-1472); Net logon (CVE-2020-1472).
CVEs exploited by RansomHub: Confluence Data Center and Server (CVE-2023-22515/Groma Explorer).
CVEs exploited by RansomHub: FortiOS (CVE-2023-27997/Groma Explorer).
CVEs exploited by RansomHub: Citrix NetScaler ADC (CVE-2023-3519).
CVEs exploited by RansomHub: SMBv1 (CVE-2017-0144).
3 more CVEs tied to this actor tracked in Mallory.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an operation whose affiliates subsequently joined Qilin; no specific RansomHub activity is described.
Its site was taken down during a background incident involving rival groups. A member subsequently defaced DragonForce's site and labeled that group 'traitors.'
Operates a ransomware-as-a-service operation active since February 2024, targeting healthcare, financial, auction-house, technology, and government entities. Its ransomware is assessed to be an updated rebrand of Knight, potentially developed from purchased source code rather than operated by Knight’s original creators. The operators reportedly recruited former ALPHV affiliates.
Affiliate-driven ransomware operation that absorbed former BlackCat affiliates; its leak site went offline in March 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.