Description
RansomHub is a ransomware operation that rose rapidly in 2024, staffed by affiliates from retired brands and renting its encryptor to experienced intrusion crews. It targets Windows, Linux, and VMware ESXi systems, exfiltrates data before encryption, and pressures victims through a leak site and aggressive negotiation. Its affiliate model and broad platform support made it one of the most active extortion brands of its era.
Stats
- First seen
- June 2024
- Last seen
- October 2026
Also known as
Ransomhub
MITRE ATT&CK techniques
21 techniques across 8 tactics.
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.RansomHub.1 |
| Linux.Ransomware.Ransomhub |
| Win32.Ransomware.Ransomhub |
| Win64.Ransomware.Ransomhub |
| Win64.Ransomware.RansomHub |
