RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture. Known victims: 193 3 ransom note(s) on file
Objectives
Executive Summary
RansomHouse is a medium-sophistication ransomware-as-a-service (RaaS) operation linked to the threat actor 'Jolly Scorpius,' active since June 2021. The group focuses on double extortion tactics, targeting organizations across healthcare, finance, transportation, and government sectors with over 193 known victims. Their recent adoption of multi-layered dual-key encryption highlights an evolution in their technical capabilities to ensure data recovery only through payment.
Goals & Targeting
RansomHouse seeks financial gain through ransomware deployment, targeting sectors with high organizational overhead or sensitive data that would incur significant disruption if unaddressed. Their focus on healthcare, finance, transportation, and government reflects an understanding of the critical nature of these industries' infrastructure and data sensitivity. The group’s victims are typically organizations that can be pressured to pay ransoms without raising immediate red flags, often due to operational continuity requirements or patient care obligations in healthcare settings.
Enhanced Description
RansomHouse operates as a criminally motivated ransomware-as-a-service (RaaS) group, primarily focusing on double extortion campaigns where victims are threatened with both data encryption and the exfiltration of sensitive information. The group's operations began in late 2021 and have expanded significantly across multiple industries, including healthcare, finance, transportation, and government sectors. Known for its association with 'Jolly Scorpius,' RansomHouse distinguishes itself through its strategic targeting of high-value assets and critical infrastructure entities. Over time, the group has demonstrated adaptability by evolving its encryption methods, transitioning to multi-layered dual-key architecture, which complicates data recovery without decryption keys. This approach underscores their intent to maximize financial gain while minimizing the likelihood of successful post-payment remediation efforts. The group's sustained activity from 2021 to July 2026 indicates a stable operational structure and willingness to adapt to defender countermeasures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RansomHouse has conducted numerous campaigns targeting diverse industries, with notable operations including 'Karl Chevrolet' and others linked to critical infrastructure. Their campaign patterns suggest a preference for prolonged lateral movement within networks to identify high-value data before encryption. The group's operational tempo is consistent with financially motivated actors, balancing stealth with the urgency required to pressure victims into timely payment decisions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in RansomHouse's operational details and targeting patterns, given the numerous linked campaigns and victims. Data gaps include specific tools used beyond known ones like Cobalt Strike and Mimikatz, as well as exact techniques employed during initial compromise phases.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
23
Campaigns
0
IOCs
0
Observed Data
0
Tactics