ransomhub logo

ransomhub

2 incidentes 2 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Water Bakunawa
Ver en IntelTracker → APTTrail →
RansomHub is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in early February 2024, distinguishing itself through an innovative affiliate payment model designed to attract members from disrupted groups. The group is assessed with moderate confidence to be Russian-based or Russian-friendly, as evidenced by its prohibition on attacking Commonwealth of Independent States (CIS) countries, Cuba, North Korea, and China. RansomHub quickly rose to prominence by recruiting former affiliates from high-profile ransomware groups such as ALPHV (BlackCat) and LockBit, offering a 90% share of ransom payments to affiliates, with affiliates managing their own wallets. This structure aimed to address trust issues prevalent in the cybercrime underground following exit scams by other RaaS operations. Security researchers widely believe RansomHub to be a successor or rebrand of the Knight ransomware, also known as Cyclops or Cyclops 2.0, due to significant code similari
Tecnicas MITRE
T1486, T1078, T1566.001, T1562.001, T1027
CVEs relacionadas
CVE-2025-8088, CVE-2025-6543, CVE-2025-61882, CVE-2025-5777, CVE-2025-53771, CVE-2025-53770

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United Kingdom (1) United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAfghanistanAlbaniaArgentinaAustriaAustraliaBangladeshBelgiumBrazilCanada

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

github.com raw.githubusercontent.com ransomware.anggipradana.com