RansomHouse
RansomHouse is a ransomware-as-a-service operation associated with the threat cluster tracked as Jolly Scorpius.
Profile source: Mallory opens in a new tabRansomHouse
Family profile
RansomHouse is a ransomware-as-a-service operation associated with the threat cluster tracked as Jolly Scorpius. First observed in 2021, it initially became known for extortion-only activity centered on data theft and threats of public disclosure, and later evolved into a double-extortion operation that combines exfiltration with file encryption. Victims publicly attributed to the operation span healthcare, finance, transportation, government, and other enterprise sectors, with a notable focus on organizations operating VMware ESXi infrastructure.
The operation uses a modular toolset that separates management and deployment from encryption. A management component known as MrAgent is used to automate activity across ESXi environments, maintain command-and-control connectivity, collect host information, execute commands, and disable defensive controls such as host firewalls. The encryptor component, known as Mario, targets virtualization- and backup-related data and has evolved from a simpler implementation into a more sophisticated scheme using dual-key, multi-stage encryption with chunked or sparse processing. This design increases operational speed against large virtual machine and backup files while complicating analysis and recovery.
RansomHouse affiliates are assessed to obtain access through spearphishing, social engineering, or exploitation of vulnerable systems, then exfiltrate sensitive data before deploying the encryptor. The group’s emphasis on ESXi enables high-impact disruption by encrypting many virtual machines from a small number of hypervisor hosts. Public reporting also links the operation to use of common post-compromise tooling for persistence and data theft in some intrusions.
RansomHouse is widely tracked as a RaaS ecosystem rather than a single monolithic intrusion set, with operators maintaining the platform and leak infrastructure while affiliates conduct intrusions. The group has been described as presenting itself as security auditors, but its activity is consistent with financially motivated cyber extortion. Recent reporting indicates continued technical investment in the malware’s encryption logic and deployment workflow, reflecting an increasingly mature enterprise-focused ransomware capability across Linux-based virtualization environments and, in broader reporting, Windows and Linux targets.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
- Initial Access
- Persistence
Operational record
Recent claims
Exploited software
Vulnerabilities linked to RansomHouse
2 CVEsMITRE ATT&CK
RansomHouse in ATT&CK
3 distinct techniquesReporting
Research mentioning RansomHouse
Ransomware Group clop Hits: HONGHE-TECH.COM
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.