The group emerged in mid-February 2024 and has already listed several organizations as alleged victims of their attacks, resulting from extortion through encryption and data leaks.<br> <br> The announcement of the sale of the new Ransomware-as-a-Service (RaaS) by RansomHub was published on one of the Russian-origin forums used by cybercrime to advertise malicious services, known as RAMP4U (or RAMP). A user with the nickname and persona of 'koley' announced the affiliate program on February 2, 2024.<br> <br> In the new RaaS announcement, it was mentioned that the money laundering operation of the paid ransoms is the responsibility of the affiliate. This means that all communication and sending of the decryptor to the victim are done through chat. The split of this RaaS would be 90% of the value for the affiliate and 10% for the developer, who in this case would be the persona of Koley.<br> <br> Furthermore, according to the publication, the ransomware payload is written in Golang language, uses the asymmetric algorithm based on x25519, and encryption algorithms AES256, ChaCha20, and xChaCha20, standing out for its speed. The encryption is obfuscated using AST.<br> <br> The payload would support network propagation and encryption of data both in secure and local mode. According to Koley, the ransomware is designed to operate on platforms such as Windows, Linux, and ESXi, as well as other architectures such as ARM and MIPS.<br> <br> As pointed out by the panel and already highlighted by the intelligence team, Koley stated that the panel uses a .onion domain, allowing the affiliate to organize and manage targets and chat rooms, view access logs, automatically respond when offline, and create private blog pages.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 842 1 negotiation log(s) available, 4 ransom note(s) on file
Objectives
Executive Summary
The ransomhub threat actor emerged in February 2024 as a new ransomware group operating a Ransomware-as-a-Service (RaaS) model. Known for their use of advanced encryption algorithms and a sophisticated affiliate program, they have targeted numerous organizations across various sectors. Their primary goals are financial gain through extortion and the sale of decryption tools to victims.
Goals & Targeting
Ransomhub's strategic focus appears to be on maximizing financial gain through the RaaS model. Their targeting profile suggests they are willing to attack any organization that offers a viable payout, with no apparent restrictions based on sector or geography. The group's technical capabilities, including support for multiple platforms and architectures, indicate an intent to expand their footprint globally. Affiliates are likely responsible for identifying targets and managing victim communications, enabling the group to scale their operations efficiently.
Enhanced Description
The ransomhub group has rapidly established itself in the cybercrime landscape since its emergence in mid-February 2024. The group operates a Ransomware-as-a-Service (RaaS) model, with the affiliate receiving 90% of the ransom proceeds and the developer retaining 10%. This structure incentivizes affiliates to actively seek targets while maintaining operational distance from the core development team. The ransomware payload is written in Golang and employs advanced encryption algorithms, including x25519 for asymmetric encryption and AES256, ChaCha20, and xChaCha20 for symmetric encryption. The use of AST obfuscation further complicates analysis and detection. Ransomhub's ransomware is designed to operate on multiple platforms, including Windows, Linux, ESXi, ARM, and MIPS architectures, demonstrating technical sophistication and versatility. Communication with victims is managed through a .onion domain, allowing for secure and anonymous interactions. The group has already targeted numerous organizations, leveraging a combination of technical expertise and business model innovation to achieve their objectives.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Ransomhub has demonstrated a high operational tempo since their emergence, with numerous victims already reported. Their affiliate program suggests a focus on scalability and decentralized targeting. Notable campaign patterns include the use of .onion domains for command and control, rapid encryption of targeted systems, and aggressive financial extortion tactics. The group's reliance on advanced encryption and obfuscation techniques indicates an intent to evade detection and persist in the threat landscape.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on ransomhub is moderately confident, with clear evidence of their activities and operational model. However, details regarding specific targeting sectors and geographic regions remain limited. Additional intelligence on their attack patterns and victimology would enhance understanding of their threat profile.
No techniques linked yet.
No tools linked yet.
New ransomware
Imported from MISP event #455 (57174526-23d8-4895-8c08-4ed1950d210f).
Apr 20, 2016
TLP:CLEARNo observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
5
IOCs
0
Observed Data
0
Tactics