Overview
Platforms:
Windows · Linux · VMware ESXi · FreeBSD
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
Phishing · Exploit Public-Facing Application
Top countries:
US · GB · DE · ES · CA
Observed sectors:
Professional Services · Technology · Manufacturing · Healthcare · Government
Tracked victims:
827
Attribution
Relationships
Knight / Cyclops
PROBABLE
Reported code and infrastructure relationship
MITRE ATT&CK reports that RansomHub operators may have acquired and rebranded resources associated with Knight, formerly Cyclops, ransomware.
Affiliates
No affiliate information available.
Activity
Initial Access
Phishing
RansomHub affiliates used mass phishing and spearphishing emails to obtain initial access.
Exploitation of public-facing applications
RansomHub affiliates exploited known vulnerabilities in internet-facing systems to obtain initial access.
Password spraying
Password spraying against exposed accounts was documented as an initial-access technique used by RansomHub affiliates.
Recent Observations
RansomHub activity ceased
April 2025
Operational change
Public leak-site activity ceased around the end of March and beginning of April 2025, with no sustained return observed through September 2026.
Joint RansomHub advisory
August 2024
Government advisory
FBI, CISA, MS-ISAC and HHS published a joint advisory documenting RansomHub tactics, techniques, vulnerabilities and indicators.
RansomHub emerges
February 2024
Operational activity
RansomHub appeared publicly as a ransomware-as-a-service operation targeting organisations across multiple sectors.
TTPs
ATT&CK coverage:
8 techniques
· 5 tactics
T1566
Phishing
VERIFIEDInitial Access
RansomHub affiliates used mass phishing and spearphishing emails to obtain initial access.
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
Known vulnerabilities in internet-facing systems were exploited by RansomHub affiliates.
T1110.003
Password Spraying
VERIFIEDCredential Access
Password spraying was used against exposed or compromised accounts.
Show more TTPs (5)
T1059.001
PowerShell
VERIFIEDExecution
PowerShell and scripts were used to automate intrusion activity.
T1021.002
SMB/Windows Admin Shares
VERIFIEDLateral Movement
RansomHub can use supplied credentials to move laterally over SMB.
T1490
Inhibit System Recovery
VERIFIEDImpact
RansomHub can delete volume shadow copies using vssadmin.
T1486
Data Encrypted for Impact
VERIFIEDImpact
RansomHub encrypts targeted files using configurable high-performance encryption.
Victims
CVEs
Citrix
— NetScaler ADC / Gateway
Observed as an initial-access vulnerability exploited by RansomHub affiliates.
Associated since:
2024
Infrastructure
RansomHub leak site
RansomHub operated Tor-hosted data leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
RansomHub negotiation portal
Victims were directed to Tor-hosted communication infrastructure using unique client identifiers for ransom negotiations.
RaaS platform
RansomHub provided affiliates with ransomware builds supporting Windows, Linux, VMware ESXi and FreeBSD environments.
Timeline
2025-04
Operation goes dark
RansomHub ceased sustained leak-site activity and did not re-establish a comparable public operation through September 2026.
2025-03
Final sustained leak-site activity
RansomHub continued publishing victim claims through the end of March 2025.
2024-08
Joint government advisory
FBI, CISA, MS-ISAC and HHS published a joint advisory documenting RansomHub tradecraft and indicators.
Show more events (1)
2024-02
RansomHub emerges
RansomHub appeared as a ransomware-as-a-service operation targeting organisations globally.