RansomHub affiliates
Ransomware-as-a-Service (RaaS) affiliates — diverse origins · Financial — ransomware and extortion
Tactics, Techniques & Procedures (TTPs)
- Affiliate-driven RaaS model (affiliates keep ~90% of ransom)
- Initial access via phishing, RDP brute force, VPN vulnerabilities
- ALPHV/BlackCat refugee affiliates post-disruption
- LockBit affiliates post-law enforcement action
- Double-extortion with dedicated leak site
- EDR evasion and disabling of security tools
Known Targets
Analyst Notes
RansomHub emerged in early 2024 and rapidly absorbed affiliates displaced by law enforcement action against ALPHV/BlackCat and LockBit. Now one of the most active RaaS platforms by victim count.
Also Known As
Intelligence Reports
RansomHub Affiliates Targeting UK Law Firms During Active M&A Mandates
Multiple UK and European law firms have been hit by RansomHub-affiliated actors during live M&A transactions. The timing is deliberate: attackers maximise leverage by striking when client pressure to resolve the incident is highest.
NHS Trusts Targeted in Coordinated Ransomware Wave as RaaS Affiliates Shift Focus
A cluster of ransomware affiliates, several previously linked to ALPHV/BlackCat, has targeted three NHS trusts in the past six weeks. Attackers are exploiting legacy VPN appliances and unpatched remote access infrastructure.