RansomHub is a cross-platform ransomware family distributed through a financially motivated ransomware-as-a-service operation that emerged in February 2024. Its payloads target Windows, Linux, and VMware ESXi environments. RansomHub shares substantial Go code, Gobfuscate obfuscation, command-line functionality, and ransom-note wording with Knight ransomware, originally known as Cyclops. Windows variants can restart endpoints in Safe Mode before encryption, reducing interference from security software.
The operation, tracked as Greenbottle, supplies ransomware and extortion infrastructure to affiliates. Its affiliate-first payment model allocates 90% of ransom proceeds to affiliates and 10% to the core operators. It recruited former ALPHV/BlackCat affiliates and became one of the most prominent ransomware operations during 2024. Scattered Spider has also deployed RansomHub, including against ESXi infrastructure.
Affiliates obtain access through phishing, password spraying, and exploitation of known vulnerabilities, including Zerologon and vulnerabilities in Citrix, Fortinet, and Confluence products. Intrusions involve network discovery, credential harvesting, account manipulation, and lateral movement using legitimate administrative and remote-access tools. RansomHub actors have used the separate EDRKillShifter tool to disable endpoint defenses through vulnerable-driver exploitation before launching the encryptor. The ransomware platform has no built-in data-exfiltration mechanism; affiliates independently steal data using external tools and services. Extortion combines encryption with threats to publish or otherwise disclose stolen information.
Victims span healthcare, manufacturing, finance, technology, government, construction, retail, and professional services worldwide, with substantial targeting in the United States. RansomHub's leak and victim-negotiation infrastructure went offline in April 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers deploying RansomHub have been seen gaining initial access to victim networks by exploiting known vulnerabilities such as the Zerologon vulnerability (CVE-2020-1472).
CitrixBleed (CVE-2023-3519): This exploit for known vulnerabilities is frequently used by RansomHub affiliates, which security researchers with Microsoft reported have shifted to using Ransomhub and Qilin ransomware operations.
The article lists “Fortinet FortiOS (CVE-2023-27997)” among known vulnerabilities exploited for initial access by attackers deploying RansomHub.
Confluence (CVE-2023-22515): This exploit is also frequently used by RansomHub affiliates.
The article lists “Java OpenWire protocol marshaller (CVE-2023-46604)” among known vulnerabilities exploited for initial access by attackers deploying RansomHub.
CVEs exploited by RansomHub: BIG-IP (CVE-2023-46747). | According to the Cybersecurity and Infrastructure Security Agency (CISA), the RansomHub ransomware-as-a-service (RaaS) platform does not provide built-in mechanisms for data exfiltration.
CVEs exploited by RansomHub: SMBv1 (CVE-2017-0144). | According to the Cybersecurity and Infrastructure Security Agency (CISA), the RansomHub ransomware-as-a-service (RaaS) platform does not provide built-in mechanisms for data exfiltration.
CVEs exploited by RansomHub: FortiClientEMS (CVE-2023-48788). | According to the Cybersecurity and Infrastructure Security Agency (CISA), the RansomHub ransomware-as-a-service (RaaS) platform does not provide built-in mechanisms for data exfiltration.
Persistence via new systemd services is a TTP documented in multiple ransomware groups, including RansomHub's campaigns using CVE-2024-1086 for post-compromise privilege escalation.
Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to the Cybersecurity and Infrastructure Security Agency (CISA), the RansomHub ransomware-as-a-service (RaaS) platform does not provide built-in mechanisms for data exfiltration.
RansomHub first appeared in February 2024, and by the third quarter of the year, it was one of the most prominent ransomware operations.
Once inside, it created its own VM within the ESXi environment to stage and deploy the “RansomHub” encryptor.
ShadowSyndicate works with numerous ransomware groups and affiliates of ransomware programs including RansomHub
The user @dragonforce ... stated, “It has been decided that RansomHub’s infrastructure will be transferred to DragonForce, and the two groups are in a partnership.”
RansomHub is one of the most prolific groups to emerge following the LockBit disruption and ALPHV (also known as BlackCat) demise in 2024.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
149 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a source of affiliates subsequently absorbed by Qilin, without details of its own malware or campaigns.
Mentioned as background to disputes among ransomware operators. No ransomware capabilities or victim attack details are provided.
A ransomware-as-a-service family active since February 2024. It shares substantial Go code, obfuscation, command-line options, and ransom-note wording with Knight. It can restart endpoints in safe mode before encryption. Its operators have exploited Zerologon and used dual-use tools before deployment. Reported victims include Change Healthcare and Christie's auction house.
An affiliate-driven ransomware operation identified as a successor destination for former BlackCat affiliates; its leak site reportedly went offline in March 2025.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.