Skip to content
← All Threat Actors
Cybercrime critical Eastern Europe (Russia-linked, assessed)

RansomHub

Ransomware-as-a-Service (RaaS) — Russian-speaking core team (assessed) · Financial — ransomware and extortion

Reports 1
Active Since 2024
Last Reported 1 Jul 2026
Sectors Targeted healthcare, critical-infrastructure, finance, manufacturing, legal-professional

Tactics, Techniques & Procedures (TTPs)

  • Dominant post-disruption RaaS — absorbed hundreds of ALPHV and LockBit affiliates in early 2024
  • 90/10 affiliate revenue split — most aggressive commission structure in the major RaaS market
  • Multi-platform encryptor: Windows, Linux, VMware ESXi, and FreeBSD from a single Go codebase
  • ChaCha20 per-file encryption with RSA-4096 key encapsulation; intermittent encryption for large files
  • Affiliate-specific initial access — VPN appliance exploitation, phishing, IAB credentials, Zerologon (CVE-2020-1472)
  • ESXi management interface targeting for multiplier effect: one host compromise encrypts entire virtual server estate
  • Data exfiltration via Rclone before encryption; backup infrastructure specifically targeted and destroyed

Known Targets

US and European healthcare organisationsCritical infrastructure operators (water utilities)Financial servicesManufacturingLegal and professional servicesChristie's, Halliburton, Kawasaki Europe, UnitedHealth Group affiliates

Analyst Notes

RansomHub launched February 2024 immediately after the FBI's Operation Cronos disrupted LockBit and the ALPHV/BlackCat core team exit-scammed affiliates out of a $22 million Change Healthcare ransom payment. Within months, RansomHub became the most prolific ransomware group globally by victim count, claiming 2,000+ victims across 80+ countries by end of 2024. The 90/10 affiliate split was explicitly designed to attract the most capable displaced affiliates. CISA issued joint advisory AA24-242A in August 2024 documenting affiliate TTPs. The non-CIS targeting policy and Russia-adjacent operational behaviour indicate a core team operating from jurisdictions with limited extradition exposure. No law enforcement disruption as of mid-2026.

Also Known As

No confirmed aliases; core team behind RaaS platform