Overview

Platforms: Windows · Linux · VMware ESXi · FreeBSD
Variants: —
Extensions: —
ATT&CK software: —
Initial access: Phishing · Exploit Public-Facing Application
Top countries: US · GB · DE · ES · CA
Observed sectors: Professional Services · Technology · Manufacturing · Healthcare · Government
Tracked victims: 827

Attribution

Relationships

Knight / Cyclops PROBABLE
Reported code and infrastructure relationship
MITRE ATT&CK reports that RansomHub operators may have acquired and rebranded resources associated with Knight, formerly Cyclops, ransomware.

Affiliates

No affiliate information available.

Activity

Initial Access

Phishing
RansomHub affiliates used mass phishing and spearphishing emails to obtain initial access.
Exploitation of public-facing applications
RansomHub affiliates exploited known vulnerabilities in internet-facing systems to obtain initial access.
Password spraying
Password spraying against exposed accounts was documented as an initial-access technique used by RansomHub affiliates.

Recent Observations

RansomHub activity ceased
April 2025
Operational change
Public leak-site activity ceased around the end of March and beginning of April 2025, with no sustained return observed through September 2026.
Joint RansomHub advisory
August 2024
Government advisory
FBI, CISA, MS-ISAC and HHS published a joint advisory documenting RansomHub tactics, techniques, vulnerabilities and indicators.
RansomHub emerges
February 2024
Operational activity
RansomHub appeared publicly as a ransomware-as-a-service operation targeting organisations across multiple sectors.

TTPs

ATT&CK coverage: 8 techniques · 5 tactics
T1566 Phishing
VERIFIED
Initial Access
RansomHub affiliates used mass phishing and spearphishing emails to obtain initial access.
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
Known vulnerabilities in internet-facing systems were exploited by RansomHub affiliates.
T1110.003 Password Spraying
VERIFIED
Credential Access
Password spraying was used against exposed or compromised accounts.
Show more TTPs (5)
T1059.001 PowerShell
VERIFIED
Execution
PowerShell and scripts were used to automate intrusion activity.
T1021.002 SMB/Windows Admin Shares
VERIFIED
Lateral Movement
RansomHub can use supplied credentials to move laterally over SMB.
T1490 Inhibit System Recovery
VERIFIED
Impact
RansomHub can delete volume shadow copies using vssadmin.
T1489 Service Stop
VERIFIED
Impact
RansomHub can terminate services before encryption.
T1486 Data Encrypted for Impact
VERIFIED
Impact
RansomHub encrypts targeted files using configurable high-performance encryption.

Victims

CVEs

Citrix — NetScaler ADC / Gateway
Observed as an initial-access vulnerability exploited by RansomHub affiliates.
Associated since: 2024

Infrastructure

RansomHub leak site
RansomHub operated Tor-hosted data leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
RansomHub negotiation portal
Victims were directed to Tor-hosted communication infrastructure using unique client identifiers for ransom negotiations.
RaaS platform
RansomHub provided affiliates with ransomware builds supporting Windows, Linux, VMware ESXi and FreeBSD environments.

Timeline

2025-04
Operation goes dark
RansomHub ceased sustained leak-site activity and did not re-establish a comparable public operation through September 2026.
2025-03
Final sustained leak-site activity
RansomHub continued publishing victim claims through the end of March 2025.
2024-08
Joint government advisory
FBI, CISA, MS-ISAC and HHS published a joint advisory documenting RansomHub tradecraft and indicators.
Show more events (1)
2024-02
RansomHub emerges
RansomHub appeared as a ransomware-as-a-service operation targeting organisations globally.

Sources

RansomHub — Software S1212
MITRE ATT&CK
Framework
#StopRansomware: RansomHub Ransomware
FBI / CISA / MS-ISAC / HHS
Government advisory
Show more sources (1)
RansomHub ransomware operation
Ransomware.live-derived tracking
Tracker