RansomHouse — Ransomware Profile

RansomHouse runs a data-theft extortion brand that posts samples of allegedly stolen corporate files to a Tor leak site. Malpedia dates its emergence to the opening quarter of 2022 and notes that early reporting could not settle whether the crew broke into victims itself or simply resold databases obtained from others; Palo Alto Unit 42, which tracks the operators as Jolly Scorpius, places the start of activity around December 2021. By Unit 42's December 2025 assessment the operation had matured into a ransomware-as-a-service structure splitting tool developers from the affiliates who run intrusions, pairing exfiltration with encryption so that victims face exposure whether or not they pay. Unit 42 singles out VMware ESXi hosts as a favoured target, since one compromised hypervisor puts every virtual machine on it within reach, and lists healthcare, finance, transportation and government among the sectors affected. At least 123 organisations had appeared on the leak site by the time of that write-up.

Also tracked as

White Rabbit, Mario ESXi

IntelFusions coverage (1)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions