Ransomware
RansomHub
First seen: 2024-02 • Status: active
Currently Active Threat
RansomHub is a new ransomware service that opened in 2024. Former members of other ransomware gangs have joined them.
Overview
RansomHub is a newer RaaS operation that emerged in 2024. It has attracted affiliates from defunct groups like BlackCat/ALPHV.
How It Spreads
- • Affiliate network
- • Various vectors
What It Does
- • File encryption
- • Data theft
- • Double extortion
Is your business exposed?
Target Platforms
Windows, Linux
Detection Tips
- • Monitor for RansomHub signatures
- • Watch emerging threat intel
MITRE ATT&CK Techniques
T1486, T1567
If You're Infected
- 1.
Follow standard ransomware response
- 2.
Engage incident response
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required