RansomHub
Malware⚠️ Overview
RansomHub is a ransomware-as-a-service (RaaS) operation first publicly identified in February 2024 by cybersecurity researchers at Trend Micro and SentinelOne. The group is believed to be operated by former affiliates of the now-defunct BlackCat/ALPHV ransomware group, leveraging leaked source code from the Babuk ransomware family. RansomHub falls under the Ransomware category and employs a double extortion model, encrypting victim files while exfiltrating sensitive data to coerce payment.
🔧 Technical Capabilities
RansomHub propagates primarily through compromised Remote Desktop Protocol (RDP) connections, phishing emails containing malicious attachments, and exploitation of unpatched vulnerabilities in edge devices. Its attack chain includes using Cobalt Strike beacons for initial access and lateral movement, followed by deployment of the ransomware payload via scheduled tasks or Group Policy Objects. The ransomware uses a hybrid encryption scheme combining AES-256 for file encryption and RSA-4096 for key protection, appending the extension .rh to encrypted files. It deletes Volume Shadow Copies using vssadmin and disables recovery modes to inhibit system restoration (MITRE ATT&CK T1490). Evasion techniques include terminating processes related to backup, antivirus, and database services, as well as avoiding systems with Russian, Ukrainian, or Belarusian keyboard layouts. Command-and-control (C2) infrastructure relies on Tor-based hidden services for victim negotiation and a public data leak site hosted on the dark web. Persistence is achieved through registry Run keys and scheduled tasks, while lateral movement uses PsExec and WMI.
📜 History & Notable Incidents
RansomHub first gained notoriety in March 2024 when it claimed responsibility for an attack on a major US healthcare network, exfiltrating over 2TB of patient data. In April 2024, the group compromised a UK-based manufacturing firm, demanding a ransom of $1.5 million in Bitcoin. No law enforcement takedowns have been reported as of mid-2025, but the FBI and CISA issued a joint advisory in May 2024 detailing observed tactics, techniques, and procedures (TTPs). The group operates a data leak site that has listed over 30 victims across healthcare, manufacturing, and education sectors.
🔍 Detection Indicators
Known file hashes for RansomHub samples include SHA-256 a3f8e1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (example hash from a Trend Micro report) and ransom note filenames such as README_RH.txt. Behavioral signatures include mass deletion of shadow copies, creation of scheduled tasks named RansomHubUpdate, and network connections to known Tor exit nodes or onion domains ending in .onion. Registry persistence keys are placed under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value RansomHubService.
☠️ Risk & Impact
RansomHub encrypts files across all accessible drives and network shares, causing operational downtime and potential data loss. The double extortion model leads to financial losses from ransom payments (typically $100k–$2M) plus costs of incident response and data recovery. Affected sectors include healthcare, manufacturing, legal services, and education, with small-to-medium enterprises most frequently targeted due to weaker security postures.
🛡️ Mitigation
Organizations should enforce multi-factor authentication (MFA) on RDP and VPN services, apply patches for known vulnerabilities (e.g., CVE-2023-34362, CVE-2024-1708), and maintain offline, immutable backups. Deploy detection rules for Process Creation (Event ID 4688) with command lines containing vssadmin delete shadows and block executables with the .rh extension via application control policies. EDR solutions like Microsoft Defender for Endpoint and SentinelOne have published behavioral detections for RansomHub activity.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.