Skip to content

RansomHub

RansomHub is a financially motivated ransomware-as-a-service operation that emerged in early 2024 and became one of the more prolific post-LockBit ransomware brands before going offline in April 2025.

Profile source: Mallory opens in a new tab

RansomHub

Family profile

RansomHub is a financially motivated ransomware-as-a-service operation that emerged in early 2024 and became one of the more prolific post-LockBit ransomware brands before going offline in April 2025. The operation used an affiliate model in which separate intrusion crews obtained access and conducted hands-on-keyboard activity before deploying the ransomware. Reporting has associated RansomHub with affiliates and partner ecosystems that also worked with other major ransomware programs, and some assessments indicate that disruption of the operation may have driven affiliate migration to competing services such as Qilin or DragonForce.

RansomHub is associated with enterprise network intrusions that culminate in data theft and ransomware deployment. Observed tradecraft around RansomHub intrusions includes rapid post-compromise execution, use of stolen or sprayed credentials, Remote Desktop Protocol access, lateral movement, credential theft, and pre-encryption impairment of endpoint defenses. The group has been linked to use of EDR-killing tooling and other defense-evasion measures intended to disable antivirus and endpoint detection products before encryption. Broader reporting also ties RansomHub-related intrusion chains to common ransomware operator tooling such as credential-dumping utilities, remote administration utilities, and lateral-movement frameworks.

Multiple delivery and access pathways have been associated with RansomHub deployments. These include password spraying followed by remote access, exploitation of public-facing vulnerabilities such as CVE-2023-46604, and malware-delivery ecosystems such as SocGholish/FakeUpdates that have served as initial access or staging mechanisms for ransomware affiliates. RansomHub has also been mentioned in connection with broader ransomware affiliate activity involving compromised remote services, stolen credentials, and access-brokered intrusions.

RansomHub primarily targets Windows enterprise environments, though the operation is best understood as a ransomware brand within a broader affiliate ecosystem rather than a single uniform intrusion set. Victimology and incident reporting place it among major ransomware threats affecting a wide range of organizations. The operation’s prominence, use of affiliate-driven intrusion tradecraft, and repeated association with defense impairment and rapid deployment made it a significant ransomware threat during 2024 and early 2025.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Post Exploitation

Operational record

1
YARA rules
4
Ransom notes
1
Negotiations
3
Leak sites
0 available

Credential Theft

  • Mimikatz

Defense Evasion

  • Acronis Disk Director
  • BadRentdrv2
  • Revo Uninstaller
  • ThreatFire System Monitor driver (BYOVD)

Discovery Enum

  • Angry IP Scanner
  • Nmap
  • SoftPerfect NetScan
  • WKTools

Exfiltration

  • FileZilla
  • PSCP
  • RClone
  • WinSCP

LOLBAS

  • BITSAdmin
  • PsExec
  • WMIC

Networking

  • Cloudflared
  • Ngrok
  • Stowaway

Offsec

  • Cobalt Strike
  • CrackMapExec
  • Impacket
  • Kerbrute
  • Metasploit
  • NetExec
  • Sliver

RMM Tools

  • AnyDesk
  • Atera
  • N-Able
  • ScreenConnect
  • Splashtop
  • TightVNC

Reported operators

Threat actors

9 named in public reporting
Scattered Spider

They've also previously partnered with other ransomware operations, such as Qilin, RansomHub, and DragonForce...

DragonForce

The user @dragonforce ... stated, “It has been decided that RansomHub’s infrastructure will be transferred to DragonForce, and the two groups are in a partnership.”

RansomHub

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

GOLD HARVEST

RansomHub is one of the most prolific groups to emerge following the LockBit disruption and ALPHV (also known as BlackCat) demise in 2024.

INDRIK SPIDER

New to the top three market share boards were RansomHub and Fog ransomware. RansomHub has been gaining share throughout 2024, despite its alleged ties to Evil Corp.

Andariel

RansomHub, a new RaaS gang that emerged around the time of Operation Cronos... It is also worth mentioning that RansomHub’s encryptor is not written from scratch, but based on repurposed code from Knight.

CosmicBeetle

RansomHub, a new RaaS gang that emerged around the time of Operation Cronos... It is also worth mentioning that RansomHub’s encryptor is not written from scratch, but based on repurposed code from Knight.

Mustard Tempest

"RansomHub is a RaaS operation that was first observed in February 2024."

ShadowSyndicate

"RansomHub is revisited with new insights on this ransomware-as-a-service (RaaS) platform... RansomHub is known for employing double extortion attacks, encrypting data using 'Curve25519' encryption."

Exploited software

Vulnerabilities linked to RansomHub

12 CVEs

MITRE ATT&CK

RansomHub in ATT&CK

96 distinct techniques

Techniques

96 techniques
T1486 Data Encrypted for Impact T1195 Supply Chain Compromise T1110.003 Password Spraying T1105 Ingress Tool Transfer T1189 Drive-by Compromise T1562.001 Disable or Modify Tools T1203 Exploitation for Client Execution T1657 Financial Theft T1567 Exfiltration Over Web Service T1562 Impair Defenses T1489 Service Stop T1059.003 Windows Command Shell T1057 Process Discovery T1547.001 Registry Run Keys / Startup Folder T1082 System Information Discovery T1497 Virtualization/Sandbox Evasion T1027 Obfuscated Files or Information T1027.013 Encrypted/Encoded File T1070.004 File Deletion T1070 Indicator Removal T1140 Deobfuscate/Decode Files or Information T1018 Remote System Discovery T1490 Inhibit System Recovery T1041 Exfiltration Over C2 Channel T1003 OS Credential Dumping T1078 Valid Accounts T1656 Impersonation T1537 Transfer Data to Cloud Account T1562.009 Safe Mode Boot T1491.001 Internal Defacement T1497.003 Time Based Checks T1135 Network Share Discovery T1059.001 PowerShell T1480 Execution Guardrails T1070.001 Clear Windows Event Logs T1090 Proxy T1021.002 SMB/Windows Admin Shares T1083 File and Directory Discovery T1078.003 Valid Accounts: Local Accounts T1190 Exploit Public-Facing Application T1566.001 Phishing: Spearphishing Attachment T1566.004 Phishing: Spearphishing Voice T1047 Windows Management Instrumentation T1059 Command and Scripting Interpreter T1059.006 Command and Scripting Interpreter: Python T1098 Account Manipulation T1133 External Remote Services T1136 Create Account T1136.001 Create Account: Local Account T1136.002 Create Account: Domain Account T1547 Boot or Logon Autostart Execution T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL T1068 Exploitation for Privilege Escalation T1548.002 Abuse Elevation Control Mechanism: Bypass UAC T1027.009 Obfuscated Files or Information: Embedded Payloads T1036 Masquerading T1055.012 Process Injection: Process Hollowing T1112 Modify Registry T1134 Access Token Manipulation T1134.001 Access Token Manipulation: Token Impersonation/Theft T1222.001 File and Directory Permissions Modification: Windows Permissions T1484.001 Domain or Tenant Policy Modification: Group Policy Modification T1564 Hidden Artifacts T1564.003 Hidden Artifacts: Hidden Window T1620 Reflective DLL Injection T1003.001 OS Credential Dumping: LSASS Memory T1003.003 OS Credential Dumping: NTDS T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow T1110 Brute Force T1555.005 Credentials from Password Stores: Password Managers T1007 System Service Discovery T1016.001 Internet Connection Discovery T1033 System Owner/User Discovery T1046 Network Service Discovery T1087 Account Discovery T1087.001 Account Discovery: Local Account T1087.002 Account Discovery: Domain Account T1120 Peripheral Device Discovery T1482 Domain Trust Discovery T1021 Remote Services T1021.001 Remote Services: Remote Desktop Protocol T1021.004 Remote Services: SSH T1210 Exploitation of Remote Services T1570 Lateral Tool Transfer T1005 Data from Local System T1048 Exfiltration Over Alternative Protocol T1048.002 Exfiltration Over Alternative Protocol: Asymmetric Encrypted Non-C2 Protocol T1048.003 Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage T1071.001 Application Layer Protocol: Web Protocols T1102.002 Web Service: Bidirectional Communication T1219 Remote Access Tools T1529 System Shutdown/Reboot T1531 Account Access Removal T1561.001 Disk Wipe: Disk Content Wipe T1586 Compromise Accounts

Reporting

Research mentioning RansomHub

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille

Jul 25
Palo Alto Networks Unit 42

Muddled Libra Threat Assessment: Further-Reaching, Faster, More Impactful

Muddled Libra—also tracked as Scattered Spider and UNC3944—resumed intrusion activity with faster, broader operations across government, retail, insurance, and aviation organizations, relying heavily on voice-based social engineering to manipulate help desks and users into resetting credentials and MFA. Investigators reported the group often minimizes malware use, abuses legitimate tools and victim-owned assets, and can move from initial access to high privilege extremely quickly, including one case where domain administrator access was reached in about 40 minutes. Since at least April 2025, the actor has also worked with the DragonForce ransomware-as-a-service program, with incidents involving large-scale data theft followed by encryption. Separate technical analysis tied the group to the bedevil (bdvl) Linux userland rootkit used against VMware vCenter servers, where it hides LD_PRELOAD persistence by patching dynamic linker binaries to reference a randomly generated preload path instead of /etc/ld.so.preload. The technique is designed to evade normal inspection tools and can restore the original linker path during uninstall or backdoor-triggered cleanup. Researchers said defenders can uncover the hidden preload path by tracing the first file access of dynamically linked binaries and can identify tampering through package integrity checks such as rpm -V glibc or debsums, while stronger Microsoft Entra ID Conditional Access policies can materially slow the group’s cloud-focused operations and reduce ransomware impact.

Oct 19
Dfir

bedevil: Dynamic Linker Patching | dfir.ch

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.