RansomHub — Malware Profile
RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least 2024 to target organizations in multiple sectors globally. RansomHub operators may have purchased and rebranded resources from Knight (formerly Cyclops) Ransomware which shares infrastructure, feature, and code overlaps with RansomHub.
MITRE ATT&CK techniques (21)
- T1018 Remote System Discovery
- T1021.002 SMB/Windows Admin Shares
- T1027.013 Encrypted/Encoded File
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1090 Proxy
- T1135 Network Share Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1480 Execution Guardrails
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1491.001 Internal Defacement
- T1497.003 Time Based Checks
- T1547.001 Registry Run Keys / Startup Folder
- T1685.005 Clear Windows Event Logs
- T1688 Safe Mode Boot
IntelFusions coverage
- Operation Cronos Fallout: LockBit Admin Panel Exposed, 193 Affiliates Identified, and Post-Disruption Activity Reveals Inflated Victim Counts 2026-02-16
- RansomHub (Knight/Cyclops Rebranded): CVE-2024-3400 and ZeroLogon in Sub-14-Hour Attack, PCHunter EDR Termination, FileZilla Exfiltration, and Multi-Platform Ransomware Variants 2026-02-16
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16