RansomHouse is a ransomware-as-a-service operation associated with the threat cluster tracked as Jolly Scorpius. First observed in 2021, it initially became known for extortion-only activity centered on data theft and threats of public disclosure, and later evolved into a double-extortion operation that combines exfiltration with file encryption. Victims publicly attributed to the operation span healthcare, finance, transportation, government, and other enterprise sectors, with a notable focus on organizations operating VMware ESXi infrastructure.
The operation uses a modular toolset that separates management and deployment from encryption. A management component known as MrAgent is used to automate activity across ESXi environments, maintain command-and-control connectivity, collect host information, execute commands, and disable defensive controls such as host firewalls. The encryptor component, known as Mario, targets virtualization- and backup-related data and has evolved from a simpler implementation into a more sophisticated scheme using dual-key, multi-stage encryption with chunked or sparse processing. This design increases operational speed against large virtual machine and backup files while complicating analysis and recovery.
RansomHouse affiliates are assessed to obtain access through spearphishing, social engineering, or exploitation of vulnerable systems, then exfiltrate sensitive data before deploying the encryptor. The group’s emphasis on ESXi enables high-impact disruption by encrypting many virtual machines from a small number of hypervisor hosts. Public reporting also links the operation to use of common post-compromise tooling for persistence and data theft in some intrusions.
RansomHouse is widely tracked as a RaaS ecosystem rather than a single monolithic intrusion set, with operators maintaining the platform and leak infrastructure while affiliates conduct intrusions. The group has been described as presenting itself as security auditors, but its activity is consistent with financially motivated cyber extortion. Recent reporting indicates continued technical investment in the malware’s encryption logic and deployment workflow, reflecting an increasingly mature enterprise-focused ransomware capability across Linux-based virtualization environments and, in broader reporting, Windows and Linux targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
I conducted a retrospective study on the vulnerability CVE-2023-4966, commonly known as Citrix Bleed, which allows attackers to easily bypass authentication in Citrix's Citrix ADC and Citrix Gateway products, over the course of six months. Initially exploited by some attackers as a zero-day in August 2023, a patch was released on October 10, followed by the publication of a PoC in late October, after which various attackers exploited the vulnerability.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation whose affiliates were reportedly partnered with Iranian actors for financially motivated activity.
Ransomware/extortion operation referenced as having affiliates that partnered with Iranian actors for monetization.
Ransomhouse is a Ransomware-as-a-Service (RaaS) operation that targets organizations, particularly those using VMware ESXi infrastructure, with advanced dual-key encryption and double extortion tactics (encryption and data theft).
Ransomware/extortion brand listed among malware observed/associated with React2Shell exploitation activity (no additional campaign detail provided in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.