EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware/ransomhub-ransomware-group-2024
116/430

File EL-0315CriticalOngoingRansomware / Ransomware-as-a-Service (RaaS) Operations

RansomHub Ransomware Operations

Also filed as RansomHub RaaS Campaign · RansomHub Cybercrime Operations

RansomHub is a prolific ransomware-as-a-service group that emerged in early 2024 following the ALPHV/BlackCat exit scam. The group rapidly became one of the most dominant ransomware operations globally, claiming over 200 victims across healthcare, energy, government, and Fortune 500 sectors.

  • #ransomware
  • #raas
  • #double-extortion
  • #critical-infrastructure
  • #healthcare
  • #data-leak-site
  • #cybercrime
Notoriety10/10
Event
1 Feb 2024
Disclosed
1 Feb 2024
Target
Multiple Victims
Actor
RansomHub
Scale
10.0M people
Status
Ongoing

01Summary

RansomHub operates a data leak site and employs sophisticated double extortion tactics — encrypting victim networks while exfiltrating terabytes of sensitive data for leverage. The group aggressively recruited former ALPHV/BlackCat affiliates after that group's exit scam, inheriting their established infrastructure, tools, and access to previously compromised networks. By late 2025, RansomHub had become the most active ransomware group globally, responsible for confirmed attacks on hospitals, energy grids, government agencies, educational institutions, and major corporations including Fortune 500 companies. Their operations span North America, Europe, Asia, and Australia, with ransom demands ranging from hundreds of thousands to tens of millions of dollars. The FBI, CISA, and multiple international law enforcement agencies have issued emergency alerts regarding RansomHub's accelerated activity and evolving tactics.

02Background

RansomHub emerged from the vacuum created by the ALPHV/BlackCat exit scam in early 2024, where the group's operators disappeared with an estimated $22 million in ransom payments leaving affiliates unpaid. Former affiliates seeking a reliable platform rapidly migrated to RansomHub, which offered competitive affiliate splits of 80-90% to affiliates, mature encryption infrastructure, and a professional dark web data leak site.

03Key revelations

  1. 01RansomHub became the most active ransomware group of 2024-2026
  2. 02Successfully recruited majority of former ALPHV/BlackCat affiliates
  3. 03Claimed over 200 victims across critical infrastructure sectors
  4. 04Estimated to have extorted over $100M USD in combined ransom payments
  5. 05FBI and CISA issued multiple emergency alerts targeting RansomHub

04Technical analysis

RansomHub utilizes a custom-built encryption binary written in Rust optimized for enterprise environments. Initial access is typically gained through exploitation of unpatched VPN appliances, compromised RDP credentials, and targeted phishing campaigns. Post-exploitation uses living-off-the-land binaries, PowerShell scripting, and Cobalt Strike for lateral movement and privilege escalation.

Attack vector
VPN appliance vulnerabilities, compromised RDP credentials, spear-phishing
Attack method
Double extortion ransomware with data exfiltration and leak site publication
Initial access
Exploitation of public-facing VPN appliances and credential theft
Lateral movement
Cobalt Strike, PowerShell, RDP
Persistence
Scheduled tasks, registry run keys
Exfiltration
Custom exfiltration tools and legitimate cloud storage services
Tool / malware
Custom Rust-based encryptor
Malware family
RansomHub
Malware type
Ransomware

Vulnerabilities exploited

  • Citrix Bleed (CVE-2023-4966)
  • Pulse Secure VPN CVEs
  • Unpatched edge devices

05Threat actor

RansomHub is a Russian-speaking ransomware group with affiliate members globally, believed to operate out of Eastern Europe. Known for professional business operations and reliable affiliate payments. Core development team estimated at 10-15 individuals with a larger affiliate network of 50-100 active members.

Attribution sources

  • BleepingComputer
  • Media reports

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Corporate documents
  • PII
  • Financial records
  • Healthcare data
  • Intellectual property
  • Customer databases
  • Employee records

08Financial damage

Ransom demands range from $100,000 to $15 million+ per victim. Estimated total extortion revenue exceeding $100 million across all claimed victims.

09Timeline

  1. 2024-02-01RansomHub emerges as primary successor to ALPHV/BlackCat following exit scam
  2. 2024-06-01RansomHub claims 100+ victims across multiple sectors
  3. 2024-09-01FBI issues first emergency alert for RansomHub IOCs
  4. 2025-01-01RansomHub surpasses 200 claimed victims, becomes most active ransomware group
  5. 2026-02-01International law enforcement operation partially disrupts RansomHub infrastructure

10Reaction and fallout

Public reaction

Widespread concern across global industries as RansomHub became the dominant ransomware threat. Healthcare sector expressed particular alarm over targeted attacks on hospitals during active treatment periods.

Political impact

Multiple government advisories issued by FBI, CISA, NCSC (UK) and international agencies. Congressional hearings cited RansomHub as primary concern. International law enforcement coordination increased through Europol and INTERPOL.

11Legal

International law enforcement operations targeting RansomHub infrastructure and affiliates underway across US, EU, UK, and Australia. Multiple active investigations with unsealed indictments expected.

12Aftermath

Policy changes

  • Enhanced mandatory ransomware payment reporting requirements
  • Stricter cybersecurity regulations for critical infrastructure

Security improvements

  • Increased enterprise adoption of MFA and zero-trust architectures
  • Improved patch management for edge devices and VPN appliances

13Significance and legacy

Significance

RansomHub represents the evolution of ransomware-as-a-service into a dominant, persistent criminal enterprise that successfully replaced its predecessors and raised the bar for enterprise defense requirements across all sectors.

Legacy

RansomHub will be remembered as the defining ransomware threat of the mid-2020s, demonstrating the remarkable resilience of the ransomware ecosystem after law enforcement takedowns of predecessor groups.

14Disclosure and media

Authentication
Breach notification and media coverage

Publishing organisations

  • BleepingComputer

15Field notes

  1. 01RansomHub explicitly recruited former ALPHV affiliates through underground forums with signing bonuses
  2. 02The group maintained a professional bug bounty program paying researchers for discovering flaws in their leak site and encryption tools
  3. 03RansomHub's ransomware binary was written in Rust, chosen for cross-platform compatibility and evasion capabilities

16Resolution

Ongoing — RansomHub remains actively operational as of May 2026. International law enforcement continues coordinated operations targeting leadership and infrastructure.

17Sources

References

  1. [1]BleepingComputer: RansomHub ransomware coverage
  2. [2]FBI Flash Alert: RansomHub IOCs
  3. [3]CISA Advisory: RansomHub
  4. [4]The Record: RansomHub becomes dominant ransomware variant
Fact sheetEL-0315

Dates

Event
1 Feb 2024
Started
1 Feb 2024
Discovered
1 Feb 2024
Disclosed
1 Feb 2024
Ongoing
Yes

Target

Organisation
Various global organizations across all sectors
Type
Multiple
Sector
Multiple Sectors
Country
Global

Actor

Name
RansomHub
Type
Criminal Gang
Motivation
Financial gain through large-scale double extortion ransomware attacks targeting critical infrastructure, healthcare, and Fortune 500 enterprises.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
10,000,000
Records
20,000,000
Volume
Multiple terabytes per victim
Sensitivity
Critical
Published
Yes
Sold (dark web)
No

Money

Ransom asked
$10,000,000
Crypto
Bitcoin and Monero

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.