In February 2024, the ransomware ecosystem was in unusual flux. The FBI’s Operation Cronos had just disrupted LockBit, the dominant platform for the previous three years. ALPHV/BlackCat, the second-largest operation, was imploding following an apparent exit scam in which the core team retained a $22 million Change Healthcare ransom payment without distributing affiliate shares. Hundreds of experienced ransomware affiliates were suddenly without a platform.
RansomHub had been waiting for this moment.
The timing of RansomHub’s launch, and the speed with which it absorbed affiliates from both disrupted operations, suggests a level of preparation that goes beyond opportunism. By mid-2024, RansomHub was the most active ransomware group globally by victim count. By the end of the year, it had claimed over 2,000 victims across 18 sectors and 80 countries. By any measure of output, RansomHub became the dominant ransomware operation of 2024-2026 — built substantially on the human and technical resources of the groups that law enforcement had spent years dismantling.
Group Overview
| Attribute | Detail |
|---|---|
| Common names | RansomHub |
| First observed | February 2024 |
| Affiliate model | RaaS; 90% to affiliate, 10% to core team |
| Encryptor language | Go (Golang) |
| Platform support | Windows, Linux, VMware ESXi, FreeBSD |
| Encryption | ChaCha20 with RSA-4096 key encapsulation |
| CISA advisory | AA24-242A (August 2024) — joint advisory from FBI, CISA, MS-ISAC, HHS |
| Primary targeting | Healthcare, critical infrastructure, government, financial services, manufacturing |
| 2024 victim count | 2,000+ claimed across 80+ countries |
| 2026 status | Active; among top two RaaS groups by victim count |
| Notable victims | UnitedHealth Group affiliates, Christie’s, Halliburton, Kawasaki Europe |
The 90/10 affiliate split is the most aggressive commission structure in the major RaaS market. LockBit operated at 80/20; ALPHV at 80/20 (with variations). RansomHub’s 90/10 split was explicitly designed to attract the best-performing affiliates from disrupted operations — and it worked. Post-LockBit and post-ALPHV, experienced affiliates who could produce large ransoms moved to RansomHub faster than to any competing platform.
The Affiliate Inheritance Model
Understanding RansomHub requires understanding what it inherited. The ransomware ecosystem is not primarily a technical phenomenon; it is a labour market. The product (ransomware software) is broadly comparable across professional RaaS platforms. The real differentiator is the quality of the affiliate workforce: experienced operators with established network access, refined tradecraft, and demonstrated ability to negotiate large ransoms.
When LockBit and ALPHV collapsed in early 2024, that workforce was immediately available. RansomHub’s ability to absorb it was a function of several factors:
Speed of launch. RansomHub was advertising for affiliates almost immediately after the disruptions, with a functional platform and competitive terms. Other potential successor operations moved more slowly or with more restrictions.
Non-CIS targeting policy. Like ALPHV and LockBit, RansomHub prohibits attacks on Russia, Commonwealth of Independent States countries, Cuba, North Korea, and China. This indicates core team alignment with Russian-speaking criminal norms and effectively limits legal exposure in jurisdictions where cooperation with law enforcement is unlikely.
Open recruitment. RansomHub explicitly recruited affiliates from disrupted programmes. Posts on dark web forums noted the platform’s availability for “experienced partners from known programmes.”
Change Healthcare connection. The ALPHV affiliate who executed the Change Healthcare attack — one of the most disruptive ransomware operations in US healthcare history — reportedly moved to RansomHub after the ALPHV exit scam and published 4 terabytes of UnitedHealth Group data through RansomHub’s leak site. This provided RansomHub with both significant publicity and demonstrated capability to attract high-impact affiliates.
Technical Profile
RansomHub’s encryptor is written in Go, consistent with the post-2022 trend toward Go and Rust for ransomware development. The same codebase compiles to native binaries for Windows, Linux, VMware ESXi (Linux variant), and FreeBSD — enabling a single affiliate deployment to target heterogeneous infrastructure.
Encryption scheme. ChaCha20 stream cipher for file content encryption; RSA-4096 for session key encapsulation. Each file receives a unique per-file ChaCha20 key. The public key embedded in the binary varies by affiliate and target configuration. Decryption requires the RSA private key held by the operator.
Intermittent encryption. For large files, RansomHub implements intermittent encryption — encrypting portions of large files rather than their entirety. This accelerates the encryption process significantly, allowing the encryptor to process more systems before detection. Intermittent encryption renders files unusable without complete decryption, achieving the same leverage as full encryption with substantially reduced dwell time before completion.
VMware ESXi targeting. The ESXi build enumerates running virtual machines via ESXi management commands, shuts them down, and encrypts the underlying VMDK files. A single compromised ESXi host can effectively destroy an entire virtualised server estate. Affiliates prioritise ESXi hosts precisely because of this multiplier effect.
FreeBSD support. FreeBSD targeting is unusual in the RaaS ecosystem. Its inclusion reflects awareness that critical network appliances, storage systems, and infrastructure components often run FreeBSD-based operating systems that are excluded from Windows/Linux-only encryptors.
Network share encryption. The Windows encryptor discovers and encrypts SMB network shares accessible from compromised systems, extending the attack surface beyond directly compromised hosts.
Defence evasion. Observed variants include techniques to terminate security software processes, disable Windows Defender, and remove Windows Shadow Copies. The specific techniques vary by affiliate — RaaS platforms typically provide a configurable encryptor builder rather than a fixed binary.
Unique victim ID. Unlike some ransomware families, RansomHub embeds a unique victim ID in the encrypted file extension and ransom note, allowing the operator to correlate victims to the correct negotiation portal.
Affiliate TTPs and Intrusion Patterns
RansomHub affiliates do not use a single consistent intrusion methodology — the affiliate model means different experienced operators bring their own established tradecraft. However, CISA’s August 2024 advisory documented consistent patterns across investigated incidents:
Initial access. Affiliate-dependent, but common vectors include:
- Exploitation of known vulnerabilities in VPN appliances (Fortinet, Citrix, Cisco ASA, Ivanti)
- Phishing leading to credential theft
- Use of initial access broker credentials purchased on dark web markets
- Exploitation of Zerologon (CVE-2020-1472) against unpatched domain controllers
Discovery. Active Directory enumeration with tools including ADFind and NetScan. Network scanning to identify high-value systems (hypervisors, backup servers, domain controllers, file servers). RansomHub affiliates are specifically noted for identifying and targeting backup infrastructure early in the intrusion.
Credential access. LSASS dumping via ProcDump, comsvcs.dll, or EDR-aware techniques. Mimikatz for credential parsing. DCSync against obtained domain admin accounts. Browser credential harvesting.
Lateral movement. PsExec and Remote Desktop Protocol (RDP) are the primary lateral movement tools. Affiliates frequently move to ESXi management hosts as a priority once domain credentials are obtained.
Persistence. Scheduled tasks, service creation, and domain account creation for persistent access during the exfiltration phase.
Data exfiltration. rclone, WinSCP, and occasionally custom tooling for data staging and exfiltration to cloud storage. The exfiltration typically precedes encryption by hours to days. CISA noted that RansomHub affiliates use Cobalt Strike, Metasploit, and similar frameworks for interactive operator access during this phase.
Encryption deployment. Domain-wide via PsExec or Group Policy. ESXi encryption handled separately with direct management access. Deployment is typically timed for weekends or overnight to maximise encrypted systems before detection.
Major Incidents
UnitedHealth Group / Change Healthcare (2024). While the initial ALPHV affiliate attack preceded RansomHub’s launch, the affiliate’s subsequent affiliation with RansomHub and publication of 4TB of stolen data through RansomHub’s leak site made this the most prominent early RansomHub-associated incident. The Change Healthcare attack disrupted prescription payments and medical claims processing across the US healthcare system for weeks.
Halliburton (August 2024). The major oilfield services company confirmed a cyberattack in August 2024 attributed to RansomHub affiliates. The attack disrupted operations at the company’s Houston headquarters and affected global network connectivity.
Christie’s (May 2024). The auction house confirmed a RansomHub attack affecting its website and internal systems, with the group threatening to publish data on 500,000+ clients including high-net-worth collectors.
Kawasaki Europe (2024). The European subsidiary confirmed a RansomHub incident, with the group claiming data exfiltration from internal systems.
Multiple US water utilities (2024-2025). CISA and the EPA issued specific guidance following RansomHub attacks on water sector operators, highlighting the group’s willingness to attack critical infrastructure with potential public health consequences.
Healthcare as a Primary Target
Healthcare’s prominence in RansomHub’s victim list warrants specific attention. DHHS HC3 has issued multiple alerts specifically addressing RansomHub targeting of healthcare organisations. The targeting rationale is straightforward: healthcare organisations hold high-value regulated data (PHI creating HIPAA exposure), typically have lower incident response maturity than financial services peers, and face strong operational pressure to restore systems rapidly.
The Change Healthcare incident demonstrated the systemic impact possible through healthcare ransomware: a single clearinghouse attack disrupting prescription claims processing nationwide. For a group actively recruiting the most capable affiliates in the ecosystem, the healthcare sector offers high-probability successful extortions with significant leverage.
Why Law Enforcement Disruption Hasn’t Worked
RansomHub has maintained operations without the law enforcement disruptions that affected LockBit and ALPHV. The reasons are structural.
The affiliate model distributes operational risk. The RansomHub core team — operators, coders, infrastructure managers — are almost certainly operating from jurisdictions with limited extradition exposure to Western law enforcement (almost certainly Russian-speaking). The affiliates span multiple geographies. Disrupting the platform requires identifying and reaching the core team, which is a harder problem than seizing a known server infrastructure.
RansomHub also appears to have learned from LockBit’s operational security failures. LockBit’s core infrastructure was more centralised than it appeared; once law enforcement had a foothold, the takedown was comprehensive. RansomHub’s infrastructure posture is unknown from public sources, but the absence of disruption despite significant law enforcement attention suggests either better operational security or better jurisdiction selection.
The affiliate inheritance model also means that even a successful disruption of RansomHub would not destroy the capability. The 90%+ of RansomHub’s operational value that lives in its affiliates would simply relocate. DragonForce, Qilin, and other active platforms would benefit, and the cycle would continue.
Defensive Priorities
Perimeter appliance patching is not optional. VPN appliances and remote access infrastructure account for a disproportionate share of RansomHub affiliate initial access. Fortinet, Citrix, Cisco, and Ivanti vulnerabilities are not theoretical: they are the documented entry points in CISA-investigated incidents. Patch cycles must be measured in days for critical vulnerabilities in internet-facing appliances, not weeks.
Protect ESXi management interfaces. ESXi management should not be reachable from general enterprise networks. The destruction multiplier of a single ESXi compromise — encrypting dozens of virtual servers simultaneously — makes protecting this interface a high-priority control.
Immutable backups, stored separately. RansomHub affiliates specifically target backup infrastructure. Backups reachable from compromised domain credentials are not recoverable backups. Offline or immutable backups, stored in a segmented environment, are the primary recovery mechanism.
Identify and remove unnecessary IAB access. Many RansomHub affiliate initial access paths begin with credentials purchased from initial access brokers. External attack surface monitoring combined with credential exposure checking (Have I Been Pwned, dark web monitoring) helps identify credentials that may be circulating.
Healthcare-specific response planning. The DHHS HC3 and CISA joint guidance for healthcare organisations is the baseline. Incident response retainers with ransomware-experienced firms are particularly important for healthcare organisations, where HIPAA regulatory notification obligations add legal complexity that must be managed alongside technical response.
RansomHub is not a temporary post-disruption winner. It has demonstrated the operational stability, technical capability, and affiliate model resilience to sustain dominance across multiple enforcement cycles. Treating it as a temporary phenomenon is a mistake. It is the current dominant threat in the ransomware ecosystem, and the correct defensive posture is to assume its affiliates are actively scanning and targeting your sector.