Malware.View on attack.mitre.org
RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least 2024 to target organizations in multiple sectors globally. RansomHub operators may have purchased and rebranded resources from Knight (formerly Cyclops) Ransomware which shares infrastructure, feature, and code overlaps with RansomHub.
| Technique | Procedure example |
|---|---|
| T1018 Remote System Discovery |
RansomHub can enumerate all accessible machines from the infected system. |
| T1021.002 SMB/Windows Admin Shares |
RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2. |
| T1027.013 Encrypted/Encoded File |
RansomHub has an encrypted configuration file. |
| T1057 Process Discovery |
RansomHub can stop processes associated with files currently in use to maximize the impact of encryption. |
| T1059.001 PowerShell |
RansomHub can use PowerShell to delete volume shadow copies. |
| T1059.003 Windows Command Shell |
RansomHub can use `cmd.exe` to execute multiple commands on infected hosts. |
| T1070.004 File Deletion |
RansomHub has the ability to self-delete. |
| T1082 System Information Discovery |
RansomHub can retrieve information about virtual machines. |
| T1083 File and Directory Discovery |
RansomHub has the ability to only encrypt specific files. |
| T1090 Proxy |
RansomHub can use a proxy to connect to remote SFTP servers. |
| T1135 Network Share Discovery |
RansomHub has the ability to target specific network shares for encryption. |
| T1140 Deobfuscate/Decode Files or Information |
RansomHub can use a provided passphrase to decrypt its configuration file. |
| T1480 Execution Guardrails |
RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration. |
| T1486 Data Encrypted for Impact |
RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files. |
| T1489 Service Stop |
RansomHub has the ability to terminate specified services. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.