RansomHub
Ransomware-as-a-Service (RaaS) — Russian-speaking core team (assessed) · Financial — ransomware and extortion
Tactics, Techniques & Procedures (TTPs)
- Dominant post-disruption RaaS — absorbed hundreds of ALPHV and LockBit affiliates in early 2024
- 90/10 affiliate revenue split — most aggressive commission structure in the major RaaS market
- Multi-platform encryptor: Windows, Linux, VMware ESXi, and FreeBSD from a single Go codebase
- ChaCha20 per-file encryption with RSA-4096 key encapsulation; intermittent encryption for large files
- Affiliate-specific initial access — VPN appliance exploitation, phishing, IAB credentials, Zerologon (CVE-2020-1472)
- ESXi management interface targeting for multiplier effect: one host compromise encrypts entire virtual server estate
- Data exfiltration via Rclone before encryption; backup infrastructure specifically targeted and destroyed
Known Targets
Analyst Notes
RansomHub launched February 2024 immediately after the FBI's Operation Cronos disrupted LockBit and the ALPHV/BlackCat core team exit-scammed affiliates out of a $22 million Change Healthcare ransom payment. Within months, RansomHub became the most prolific ransomware group globally by victim count, claiming 2,000+ victims across 80+ countries by end of 2024. The 90/10 affiliate split was explicitly designed to attract the most capable displaced affiliates. CISA issued joint advisory AA24-242A in August 2024 documenting affiliate TTPs. The non-CIS targeting policy and Russia-adjacent operational behaviour indicate a core team operating from jurisdictions with limited extradition exposure. No law enforcement disruption as of mid-2026.
Also Known As