Ransomware

RansomHub

First seen: 2024-02 • Status: active

Currently Active Threat

RansomHub is a new ransomware service that opened in 2024. Former members of other ransomware gangs have joined them.

Overview

RansomHub is a newer RaaS operation that emerged in 2024. It has attracted affiliates from defunct groups like BlackCat/ALPHV.

How It Spreads

  • Affiliate network
  • Various vectors

What It Does

  • File encryption
  • Data theft
  • Double extortion

Is your business exposed?

Target Platforms

Windows, Linux

Detection Tips

  • Monitor for RansomHub signatures
  • Watch emerging threat intel

MITRE ATT&CK Techniques

T1486, T1567

If You're Infected

  1. 1.

    Follow standard ransomware response

  2. 2.

    Engage incident response

Related Malware

Blackcat, Lockbit

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required