RansomHub

S1212

Malware.View on attack.mitre.org

About this malware

RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least 2024 to target organizations in multiple sectors globally. RansomHub operators may have purchased and rebranded resources from Knight (formerly Cyclops) Ransomware which shares infrastructure, feature, and code overlaps with RansomHub.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1018
Remote System Discovery

RansomHub can enumerate all accessible machines from the infected system.

T1021.002
SMB/Windows Admin Shares

RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2.

T1027.013
Encrypted/Encoded File

RansomHub has an encrypted configuration file.

T1057
Process Discovery

RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.

T1059.001
PowerShell

RansomHub can use PowerShell to delete volume shadow copies.

T1059.003
Windows Command Shell

RansomHub can use `cmd.exe` to execute multiple commands on infected hosts.

T1070.004
File Deletion

RansomHub has the ability to self-delete.

T1082
System Information Discovery

RansomHub can retrieve information about virtual machines.

T1083
File and Directory Discovery

RansomHub has the ability to only encrypt specific files.

T1090
Proxy

RansomHub can use a proxy to connect to remote SFTP servers.

T1135
Network Share Discovery

RansomHub has the ability to target specific network shares for encryption.

T1140
Deobfuscate/Decode Files or Information

RansomHub can use a provided passphrase to decrypt its configuration file.

T1480
Execution Guardrails

RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration.

T1486
Data Encrypted for Impact

RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files.

T1489
Service Stop

RansomHub has the ability to terminate specified services.

View all 21 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. CISA RansomHub AUG 2024 Open source
    CISA et al. (2024, August 29). #StopRansomware: RansomHub Ransomware. Retrieved March 17, 2025.
  2. Group-IB RansomHub FEB 2025 Open source
    Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.