Netskope Threat Labs

RansomHub

ATP Sandbox Adv. HeuristicsAVNetskope IPS

RansomHub is a ransomware operation that rose rapidly in 2024, staffed by affiliates from retired brands and renting its encryptor to experienced intrusion crews. It targets Windows, Linux, and VMware ESXi systems, exfiltrates data before encryption, and pressures victims through a leak site and aggressive negotiation. Its affiliate model and broad platform support made it one of the most active extortion brands of its era.

First seen
June 2024
Last seen
October 2026
Ransomhub

21 techniques across 8 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1018Remote System Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1135Network Share Discovery

TA0008 Lateral Movement

TA0011 Command and Control

TA0040 Impact

TA0112 Defense Impairment

Alert Name
Gen:Variant.Ransom.RansomHub.1
Linux.Ransomware.Ransomhub
Win32.Ransomware.Ransomhub
Win64.Ransomware.Ransomhub
Win64.Ransomware.RansomHub