RansomHub
MITRE ATT&CK: S1212 View on attack.mitre.org
Aliases: RansomHub
- First seen
- 2024-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- linux, windows
- Related IoCs
- 57 (18 malicious)
- Last IoC activity
- 2026-09-01 20:37:52
- Profile updated
- 2026-07-07 13:11:54
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications manufacturing government-and-public-sector
Context
RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least 2024 to target organizations in multiple sectors globally. RansomHub operators may have purchased and rebranded resources from Knight (formerly Cyclops) Ransomware which shares infrastructure, feature, and code overlaps with RansomHub.
Recent IoC activity
18 malicious indicators in Maltiverse are attributed to RansomHub (S1212). The 18 most recently updated:
Detection coverage
- 1 YARA rules
- 462 Sigma rules
Malware & tools used
- File Deletion (attack-pattern)
- Proxy (attack-pattern)
- Execution Guardrails (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Remote System Discovery (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Time Based Checks (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Process Discovery (attack-pattern)
- Internal Defacement (attack-pattern)
- Network Share Discovery (attack-pattern)
- Safe Mode Boot (attack-pattern)
- Service Stop (attack-pattern)
- System Information Discovery (attack-pattern)
- PowerShell (attack-pattern)
Detection rules
- MALPEDIA_Win_Ransomhub_Auto (yara-rule)
Reports & references
- services.google.com — M Trends 2025 En (report)
- Broadcom/Symantec — Ransomhub Knight Ransomware (report)
- sentinelone.com — Ransomware Evolution How Cheated Affiliates Are Recycling Victim Data For Profit (report)
- catalyst.prodaft.com — Overview (report)
- services.google.com — Threat Horizons Report H1 2025 (report)
- Trend Micro — How Ransomhub Ransomware Uses Edrkillshifter To Disable Edr And (report)
- cloud.google.com — Unc3944 Proactive Hardening Recommendations (report)
- ransomlook.io — Ransomhub (report)
- linkedin.com — Ransomhub Ransomware Deploys Malware Breach Corporate Hb44C (report)
- Trend Micro — Socgholishs Intrusion Techniques Facilitate Distribution Of Rans (report)
- intrinsec.com — Tlp Clear 31072025 Shadowsyndicate Infrastructure Illumination En (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ransomhub (report)
- blog.bushidotoken.net — Tracking Adversaries Evilcorp Ransomhub (report)
- group-ib.com — Ransomhub Never Sleeps Episode 1 (report)
- MITRE ATT&CK — S1212 (report)
- CISA — Aa24 242A Stopransomware Ransomhub Ransomware 1 (report)