Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ransomhub

Description

The group emerged in mid-February 2024 and has already listed several organizations as alleged victims of their attacks, resulting from extortion through encryption and data leaks.<br> <br> The announcement of the sale of the new Ransomware-as-a-Service (RaaS) by RansomHub was published on one of the Russian-origin forums used by cybercrime to advertise malicious services, known as RAMP4U (or RAMP). A user with the nickname and persona of 'koley' announced the affiliate program on February 2, 2024.<br> <br> In the new RaaS announcement, it was mentioned that the money laundering operation of the paid ransoms is the responsibility of the affiliate. This means that all communication and sending of the decryptor to the victim are done through chat. The split of this RaaS would be 90% of the value for the affiliate and 10% for the developer, who in this case would be the persona of Koley.<br> <br> Furthermore, according to the publication, the ransomware payload is written in Golang language, uses the asymmetric algorithm based on x25519, and encryption algorithms AES256, ChaCha20, and xChaCha20, standing out for its speed. The encryption is obfuscated using AST.<br> <br> The payload would support network propagation and encryption of data both in secure and local mode. According to Koley, the ransomware is designed to operate on platforms such as Windows, Linux, and ESXi, as well as other architectures such as ARM and MIPS.<br> <br> As pointed out by the panel and already highlighted by the intelligence team, Koley stated that the panel uses a .onion domain, allowing the affiliate to organize and manage targets and chat rooms, view access logs, automatically respond when offline, and create private blog pages.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 842 1 negotiation log(s) available, 4 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The ransomhub threat actor emerged in February 2024 as a new ransomware group operating a Ransomware-as-a-Service (RaaS) model. Known for their use of advanced encryption algorithms and a sophisticated affiliate program, they have targeted numerous organizations across various sectors. Their primary goals are financial gain through extortion and the sale of decryption tools to victims.

Goals & Targeting

Ransomhub's strategic focus appears to be on maximizing financial gain through the RaaS model. Their targeting profile suggests they are willing to attack any organization that offers a viable payout, with no apparent restrictions based on sector or geography. The group's technical capabilities, including support for multiple platforms and architectures, indicate an intent to expand their footprint globally. Affiliates are likely responsible for identifying targets and managing victim communications, enabling the group to scale their operations efficiently.

Enhanced Description

The ransomhub group has rapidly established itself in the cybercrime landscape since its emergence in mid-February 2024. The group operates a Ransomware-as-a-Service (RaaS) model, with the affiliate receiving 90% of the ransom proceeds and the developer retaining 10%. This structure incentivizes affiliates to actively seek targets while maintaining operational distance from the core development team. The ransomware payload is written in Golang and employs advanced encryption algorithms, including x25519 for asymmetric encryption and AES256, ChaCha20, and xChaCha20 for symmetric encryption. The use of AST obfuscation further complicates analysis and detection. Ransomhub's ransomware is designed to operate on multiple platforms, including Windows, Linux, ESXi, ARM, and MIPS architectures, demonstrating technical sophistication and versatility. Communication with victims is managed through a .onion domain, allowing for secure and anonymous interactions. The group has already targeted numerous organizations, leveraging a combination of technical expertise and business model innovation to achieve their objectives.

Key Capabilities

  • Development and distribution of ransomware payloads
  • Support for multiple operating systems (Windows, Linux, ESXi)
  • Encryption using advanced algorithms (x25519, AES256, ChaCha20, xChaCha20)
  • Obfuscation techniques to evade detection
  • Use of .onion domains for command and control
  • Ransomware-as-a-Service model with affiliate program

MITRE ATT&CK Tactics

Ransomware
Credential Access
Defense Evasion
Disruptive Activities

ATT&CK Techniques

T1566.001
T1078
T1036
T1496.001
T1048
T1504

Software / Tooling

Custom ransomware (Golang-based)
.onion domain infrastructure
TOR communication channels

Campaigns & Victims

Ransomhub has demonstrated a high operational tempo since their emergence, with numerous victims already reported. Their affiliate program suggests a focus on scalability and decentralized targeting. Notable campaign patterns include the use of .onion domains for command and control, rapid encryption of targeted systems, and aggressive financial extortion tactics. The group's reliance on advanced encryption and obfuscation techniques indicates an intent to evade detection and persist in the threat landscape.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • .onion domain usage for command and control
  • Ransomware payloads leveraging Golang-based executables
  • Network traffic encrypted over Tor
  • High volume of file encryption across systems

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions
  • Monitor network traffic for known Indicators of Compromise (IOCs)
  • Enforce multi-factor authentication (MFA) for critical systems
  • Regularly back up data and store backups offline
  • Educate employees on phishing and ransomware防范 techniques
  • Establish incident response plans to handle ransomware incidents

Suggested Tags

ransomware
affiliate-program
RaaS
financial-gain
cyber-crime

Confidence Assessment

The data on ransomhub is moderately confident, with clear evidence of their activities and operational model. However, details regarding specific targeting sectors and geographic regions remain limited. Additional intelligence on their attack patterns and victimology would enhance understanding of their threat profile.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

5

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
affiliate-program
RaaS
financial-gain
cyber-crime

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 9, 2023
Last Seen
Mar 31, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.