RansomHub is a ransomware-as-a-service operation that emerged in early 2024 and became one of the most prolific post-LockBit ransomware brands before going offline in April 2025. It operated through an affiliate model in which core operators provided ransomware tooling and extortion infrastructure while affiliates conducted intrusions, stole data, and deployed the encryptor in victim environments. The group has been associated with financially motivated double-extortion activity and has been linked to a broad affiliate ecosystem that overlapped with other major ransomware programs.
RansomHub intrusions have been observed following multiple access paths and precursor activity rather than a single consistent delivery mechanism. Reported chains include password spraying followed by remote desktop access, exploitation of public-facing vulnerabilities, and delivery through malware distribution ecosystems such as SocGholish/FakeUpdates. The operation has also been associated with affiliates and intrusion sets that use phishing and social-engineering-driven access, as well as commodity and legitimate administrative tooling during post-compromise operations.
Observed tradecraft associated with RansomHub deployments includes credential theft, lateral movement, defense evasion, and data exfiltration prior to encryption. Reporting links RansomHub activity to use of tools such as PsExec, Mimikatz, NirSoft credential-recovery utilities, and endpoint-security-disabling tooling including EDR-killer components. Pre-encryption behavior associated with the broader ecosystem includes stopping security products and backup services, impairing endpoint defenses, and using remote administration or remote desktop access to spread within networks.
RansomHub has been tied to a diverse criminal ecosystem. It has been associated with affiliates or infrastructure overlaps involving ShadowSyndicate, TA569-linked SocGholish delivery chains, and partnerships or affiliate participation by actors such as Scattered Spider in some reporting. Multiple reports indicate that after RansomHub ceased operations in April 2025, some affiliates likely migrated to other ransomware programs, especially Qilin, and there were public claims of infrastructure transfer or partnership involving DragonForce. The operation was also discussed in connection with high-profile healthcare extortion activity, including a secondary extortion attempt tied to data retained by an affiliate after an earlier ransom payment to another ransomware group.
RansomHub primarily targeted Windows enterprise environments and was deployed in broader network intrusions affecting organizations across sectors, with reporting indicating significant impact on healthcare and other enterprise victims. It is best characterized as a major 2024-2025 RaaS brand whose success derived from affiliate scale, flexible intrusion pathways, and integration with the wider cybercriminal access and malware-delivery ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Persistence via new systemd services is a TTP documented in multiple ransomware groups, including RansomHub's campaigns using CVE-2024-1086 for post-compromise privilege escalation.
Red Canary detected an adversary executing discovery commands on dozens of cloud-based Linux endpoints vulnerable to a critical remote code vulnerability (CVE-2023-46604) in Apache ActiveMQ... Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware, along with Kinsing... Finally, the adversary used curl to download two ActiveMQ JAR files... These two JAR files constitute a legitimate patch for CVE-2023-46604. | Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware...
Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ShadowSyndicate works with numerous ransomware groups and affiliates of ransomware programs including RansomHub
They've also previously partnered with other ransomware operations, such as Qilin, RansomHub, and DragonForce...
The user @dragonforce ... stated, “It has been decided that RansomHub’s infrastructure will be transferred to DragonForce, and the two groups are in a partnership.”
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
RansomHub is one of the most prolific groups to emerge following the LockBit disruption and ALPHV (also known as BlackCat) demise in 2024.
New to the top three market share boards were RansomHub and Fog ransomware. RansomHub has been gaining share throughout 2024, despite its alleged ties to Evil Corp.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Operators leveraged compromised valid accounts in 75 percent of ransomware engagements this quarter to obtain initial access and/or execute ransomware on targeted systems.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
Operators leveraged compromised valid accounts in 75 percent of ransomware engagements this quarter to obtain initial access and/or execute ransomware on targeted systems.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.
Operators leveraged compromised valid accounts in 75 percent of ransomware engagements this quarter to obtain initial access and/or execute ransomware on targeted systems.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
Operators leveraged compromised valid accounts in 75 percent of ransomware engagements this quarter to obtain initial access and/or execute ransomware on targeted systems.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
GTIG observed confirmed or suspected data theft in approximately 77% of ransomware intrusions — a steep jump from 57% the year before. Attackers now frequently steal sensitive files before deploying encryption, threatening to post the stolen data publicly on leak sites even if victims manage to restore their systems from backup.
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. | Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain.
Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. LockBit 3.0 can identify and terminate specific services. RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
127 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware/extortion group that the former affiliate joined after the BlackCat payment dispute, and which then attempted a second extortion of UHG.
Referenced as an earlier ransomware case involving EDR and antivirus bypass; mentioned for comparison/background rather than as a main focus of this reference.
A named ransomware operation that DevMan reportedly used as an affiliate relationship prior to creating its own service.
A ransomware family/group cited as an example of successful ransomware operations over the past 18 months.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.