Credential Theft
- Mimikatz
RansomHub is a financially motivated ransomware-as-a-service operation that emerged in early 2024 and became one of the more prolific post-LockBit ransomware brands before going offline in April 2025.
Profile source: Mallory opens in a new tabRansomHub
RansomHub is a financially motivated ransomware-as-a-service operation that emerged in early 2024 and became one of the more prolific post-LockBit ransomware brands before going offline in April 2025. The operation used an affiliate model in which separate intrusion crews obtained access and conducted hands-on-keyboard activity before deploying the ransomware. Reporting has associated RansomHub with affiliates and partner ecosystems that also worked with other major ransomware programs, and some assessments indicate that disruption of the operation may have driven affiliate migration to competing services such as Qilin or DragonForce.
RansomHub is associated with enterprise network intrusions that culminate in data theft and ransomware deployment. Observed tradecraft around RansomHub intrusions includes rapid post-compromise execution, use of stolen or sprayed credentials, Remote Desktop Protocol access, lateral movement, credential theft, and pre-encryption impairment of endpoint defenses. The group has been linked to use of EDR-killing tooling and other defense-evasion measures intended to disable antivirus and endpoint detection products before encryption. Broader reporting also ties RansomHub-related intrusion chains to common ransomware operator tooling such as credential-dumping utilities, remote administration utilities, and lateral-movement frameworks.
Multiple delivery and access pathways have been associated with RansomHub deployments. These include password spraying followed by remote access, exploitation of public-facing vulnerabilities such as CVE-2023-46604, and malware-delivery ecosystems such as SocGholish/FakeUpdates that have served as initial access or staging mechanisms for ransomware affiliates. RansomHub has also been mentioned in connection with broader ransomware affiliate activity involving compromised remote services, stolen credentials, and access-brokered intrusions.
RansomHub primarily targets Windows enterprise environments, though the operation is best understood as a ransomware brand within a broader affiliate ecosystem rather than a single uniform intrusion set. Victimology and incident reporting place it among major ransomware threats affecting a wide range of organizations. The operation’s prominence, use of affiliate-driven intrusion tradecraft, and repeated association with defense impairment and rapid deployment made it a significant ransomware threat during 2024 and early 2025.
Reported operators
They've also previously partnered with other ransomware operations, such as Qilin, RansomHub, and DragonForce...
The user @dragonforce ... stated, “It has been decided that RansomHub’s infrastructure will be transferred to DragonForce, and the two groups are in a partnership.”
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
RansomHub is one of the most prolific groups to emerge following the LockBit disruption and ALPHV (also known as BlackCat) demise in 2024.
New to the top three market share boards were RansomHub and Fog ransomware. RansomHub has been gaining share throughout 2024, despite its alleged ties to Evil Corp.
RansomHub, a new RaaS gang that emerged around the time of Operation Cronos... It is also worth mentioning that RansomHub’s encryptor is not written from scratch, but based on repurposed code from Knight.
RansomHub, a new RaaS gang that emerged around the time of Operation Cronos... It is also worth mentioning that RansomHub’s encryptor is not written from scratch, but based on repurposed code from Knight.
"RansomHub is a RaaS operation that was first observed in February 2024."
"RansomHub is revisited with new insights on this ransomware-as-a-service (RaaS) platform... RansomHub is known for employing double extortion attacks, encrypting data using 'Curve25519' encryption."
Exploited software
MITRE ATT&CK
Reporting
Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.
Muddled Libra—also tracked as Scattered Spider and UNC3944—resumed intrusion activity with faster, broader operations across government, retail, insurance, and aviation organizations, relying heavily on voice-based social engineering to manipulate help desks and users into resetting credentials and MFA. Investigators reported the group often minimizes malware use, abuses legitimate tools and victim-owned assets, and can move from initial access to high privilege extremely quickly, including one case where domain administrator access was reached in about 40 minutes. Since at least April 2025, the actor has also worked with the DragonForce ransomware-as-a-service program, with incidents involving large-scale data theft followed by encryption. Separate technical analysis tied the group to the bedevil (bdvl) Linux userland rootkit used against VMware vCenter servers, where it hides LD_PRELOAD persistence by patching dynamic linker binaries to reference a randomly generated preload path instead of /etc/ld.so.preload. The technique is designed to evade normal inspection tools and can restore the original linker path during uninstall or backdoor-triggered cleanup. Researchers said defenders can uncover the hidden preload path by tracing the first file access of dynamically linked binaries and can identify tampering through package integrity checks such as rpm -V glibc or debsums, while stronger Microsoft Entra ID Conditional Access policies can materially slow the group’s cloud-focused operations and reduce ransomware impact.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.