01Summary
RansomHub operates a data leak site and employs sophisticated double extortion tactics — encrypting victim networks while exfiltrating terabytes of sensitive data for leverage. The group aggressively recruited former ALPHV/BlackCat affiliates after that group's exit scam, inheriting their established infrastructure, tools, and access to previously compromised networks. By late 2025, RansomHub had become the most active ransomware group globally, responsible for confirmed attacks on hospitals, energy grids, government agencies, educational institutions, and major corporations including Fortune 500 companies. Their operations span North America, Europe, Asia, and Australia, with ransom demands ranging from hundreds of thousands to tens of millions of dollars. The FBI, CISA, and multiple international law enforcement agencies have issued emergency alerts regarding RansomHub's accelerated activity and evolving tactics.
02Background
RansomHub emerged from the vacuum created by the ALPHV/BlackCat exit scam in early 2024, where the group's operators disappeared with an estimated $22 million in ransom payments leaving affiliates unpaid. Former affiliates seeking a reliable platform rapidly migrated to RansomHub, which offered competitive affiliate splits of 80-90% to affiliates, mature encryption infrastructure, and a professional dark web data leak site.
03Key revelations
- 01RansomHub became the most active ransomware group of 2024-2026
- 02Successfully recruited majority of former ALPHV/BlackCat affiliates
- 03Claimed over 200 victims across critical infrastructure sectors
- 04Estimated to have extorted over $100M USD in combined ransom payments
- 05FBI and CISA issued multiple emergency alerts targeting RansomHub
04Technical analysis
RansomHub utilizes a custom-built encryption binary written in Rust optimized for enterprise environments. Initial access is typically gained through exploitation of unpatched VPN appliances, compromised RDP credentials, and targeted phishing campaigns. Post-exploitation uses living-off-the-land binaries, PowerShell scripting, and Cobalt Strike for lateral movement and privilege escalation.
- Attack vector
- VPN appliance vulnerabilities, compromised RDP credentials, spear-phishing
- Attack method
- Double extortion ransomware with data exfiltration and leak site publication
- Initial access
- Exploitation of public-facing VPN appliances and credential theft
- Lateral movement
- Cobalt Strike, PowerShell, RDP
- Persistence
- Scheduled tasks, registry run keys
- Exfiltration
- Custom exfiltration tools and legitimate cloud storage services
- Tool / malware
- Custom Rust-based encryptor
- Malware family
- RansomHub
- Malware type
- Ransomware
Vulnerabilities exploited
- Citrix Bleed (CVE-2023-4966)
- Pulse Secure VPN CVEs
- Unpatched edge devices
05Threat actor
RansomHub is a Russian-speaking ransomware group with affiliate members globally, believed to operate out of Eastern Europe. Known for professional business operations and reliable affiliate payments. Core development team estimated at 10-15 individuals with a larger affiliate network of 50-100 active members.
Attribution sources
- BleepingComputer
- Media reports
06Victims and impact
Countries affected
- Global
07Data exposed
Data types
- Corporate documents
- PII
- Financial records
- Healthcare data
- Intellectual property
- Customer databases
- Employee records
08Financial damage
Ransom demands range from $100,000 to $15 million+ per victim. Estimated total extortion revenue exceeding $100 million across all claimed victims.
09Timeline
- 2024-02-01RansomHub emerges as primary successor to ALPHV/BlackCat following exit scam
- 2024-06-01RansomHub claims 100+ victims across multiple sectors
- 2024-09-01FBI issues first emergency alert for RansomHub IOCs
- 2025-01-01RansomHub surpasses 200 claimed victims, becomes most active ransomware group
- 2026-02-01International law enforcement operation partially disrupts RansomHub infrastructure
10Reaction and fallout
Public reaction
Widespread concern across global industries as RansomHub became the dominant ransomware threat. Healthcare sector expressed particular alarm over targeted attacks on hospitals during active treatment periods.
Political impact
Multiple government advisories issued by FBI, CISA, NCSC (UK) and international agencies. Congressional hearings cited RansomHub as primary concern. International law enforcement coordination increased through Europol and INTERPOL.
11Legal
International law enforcement operations targeting RansomHub infrastructure and affiliates underway across US, EU, UK, and Australia. Multiple active investigations with unsealed indictments expected.
12Aftermath
Policy changes
- Enhanced mandatory ransomware payment reporting requirements
- Stricter cybersecurity regulations for critical infrastructure
Security improvements
- Increased enterprise adoption of MFA and zero-trust architectures
- Improved patch management for edge devices and VPN appliances
13Significance and legacy
Significance
RansomHub represents the evolution of ransomware-as-a-service into a dominant, persistent criminal enterprise that successfully replaced its predecessors and raised the bar for enterprise defense requirements across all sectors.
Legacy
RansomHub will be remembered as the defining ransomware threat of the mid-2020s, demonstrating the remarkable resilience of the ransomware ecosystem after law enforcement takedowns of predecessor groups.
14Disclosure and media
- Authentication
- Breach notification and media coverage
Publishing organisations
- BleepingComputer
15Field notes
- 01RansomHub explicitly recruited former ALPHV affiliates through underground forums with signing bonuses
- 02The group maintained a professional bug bounty program paying researchers for discovering flaws in their leak site and encryption tools
- 03RansomHub's ransomware binary was written in Rust, chosen for cross-platform compatibility and evasion capabilities
16Resolution
Ongoing — RansomHub remains actively operational as of May 2026. International law enforcement continues coordinated operations targeting leadership and infrastructure.
17Sources
References
- [1]BleepingComputer: RansomHub ransomware coverage
- [2]FBI Flash Alert: RansomHub IOCs
- [3]CISA Advisory: RansomHub
- [4]The Record: RansomHub becomes dominant ransomware variant









