RansomHub
Low ConfidenceHigh ThreatCyclops • Knight
RansomHub is a ransomware-as-a-service operation that emerged in early 2024, quickly becoming one of the most active ransomware groups. The operation attracts affiliates with favorable profit-sharing terms and has targeted organizations across healthcare, government, and critical infrastructure sectors. RansomHub employs double extortion tactics and maintains a leak site for publishing stolen data from non-paying victims.
RansomHub is a ransomware-as-a-service operation that emerged in early 2024, quickly becoming one of the most active ransomware groups. The operation attracts affiliates with favorable profit-sharing terms and has targeted organizations across healthcare, government, and critical infrastructure sectors. RansomHub employs double extortion tactics and maintains a leak site for publishing stolen data from non-paying victims.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Unknown). Attribution confidence: Low.
Future Outlook
RansomHub is expected to continue operations targeting Healthcare sectors.
First observed activity of RansomHub
Continued active operations