Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ransomhouse

Description

RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture. Known victims: 193 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

RansomHouse is a medium-sophistication ransomware-as-a-service (RaaS) operation linked to the threat actor 'Jolly Scorpius,' active since June 2021. The group focuses on double extortion tactics, targeting organizations across healthcare, finance, transportation, and government sectors with over 193 known victims. Their recent adoption of multi-layered dual-key encryption highlights an evolution in their technical capabilities to ensure data recovery only through payment.

Goals & Targeting

RansomHouse seeks financial gain through ransomware deployment, targeting sectors with high organizational overhead or sensitive data that would incur significant disruption if unaddressed. Their focus on healthcare, finance, transportation, and government reflects an understanding of the critical nature of these industries' infrastructure and data sensitivity. The group’s victims are typically organizations that can be pressured to pay ransoms without raising immediate red flags, often due to operational continuity requirements or patient care obligations in healthcare settings.

Enhanced Description

RansomHouse operates as a criminally motivated ransomware-as-a-service (RaaS) group, primarily focusing on double extortion campaigns where victims are threatened with both data encryption and the exfiltration of sensitive information. The group's operations began in late 2021 and have expanded significantly across multiple industries, including healthcare, finance, transportation, and government sectors. Known for its association with 'Jolly Scorpius,' RansomHouse distinguishes itself through its strategic targeting of high-value assets and critical infrastructure entities. Over time, the group has demonstrated adaptability by evolving its encryption methods, transitioning to multi-layered dual-key architecture, which complicates data recovery without decryption keys. This approach underscores their intent to maximize financial gain while minimizing the likelihood of successful post-payment remediation efforts. The group's sustained activity from 2021 to July 2026 indicates a stable operational structure and willingness to adapt to defender countermeasures.

Key Capabilities

  • Ransomware deployment
  • Double extortion tactics
  • Multi-layered encryption techniques
  • Phishing and social engineering
  • Spear-phishing campaigns

MITRE ATT&CK Tactics

Exfiltration of Data
Data Destruction
Credential Access
Initial Access

ATT&CK Techniques

T1566.002
T1059
T1486.003
T1070.001

Software / Tooling

Cobalt Strike
Mimikatz
RansomHouse Ransomware

Campaigns & Victims

RansomHouse has conducted numerous campaigns targeting diverse industries, with notable operations including 'Karl Chevrolet' and others linked to critical infrastructure. Their campaign patterns suggest a preference for prolonged lateral movement within networks to identify high-value data before encryption. The group's operational tempo is consistent with financially motivated actors, balancing stealth with the urgency required to pressure victims into timely payment decisions.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Payload delivery via double extortion ransomware
  • Multi-layered encryption of victim data
  • Exfiltration of sensitive files prior to encryption

Recommended Actions

  • Enhance endpoint detection and response (EDR) capabilities to identify Cobalt Strike and Mimikatz activity
  • Implement strict email filtering to prevent phishing emails with malicious macros or links
  • Conduct regular backups, ensuring they are air-gapped from network access
  • Monitor for unusual network traffic indicative of multi-stage attacks

Suggested Tags

Ransomware
Financial-Motivation
Healthcare-Targeted
Critical-Infrastructure

Confidence Assessment

High confidence in RansomHouse's operational details and targeting patterns, given the numerous linked campaigns and victims. Data gaps include specific tools used beyond known ones like Cobalt Strike and Mimikatz, as well as exact techniques employed during initial compromise phases.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

23

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Government Targeting
Financial-Motivation
Healthcare-Targeted
Critical-Infrastructure

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 1, 2021
Last Seen
Aug 3, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.