Skip to content

โ€” RansomHub

Threat-actor battle card ยท maintained from public sources ยท last updated 2026-09-05 ยท also known as Knight (code ancestor), Cyclops (Knight predecessor)

CategoryRansomware-as-a-Service
AttributionUnknown; encryptor assessed as a modified fork of Knight ransomware (whose source code was sold February 2024); Evil Corp (Manatee Tempest/SocGholish) confirmed as an affiliate from July 2024; country of origin unconfirmed
First seen2024-02
StatusInactive
Primary targetsHealthcare, Government services, Manufacturing, Financial services, Critical infrastructure (water/wastewater, energy, transportation, emergency services, communications, food/agriculture)

Overview

RansomHub launched in February 2024 and grew faster than any RaaS in recorded history, reaching the top position globally by Q4 2024 before going dark on April 1, 2025. Its encryptor is widely assessed to be a modified fork of Knight ransomware (itself a Cyclops rebrand), whose version 3.0 source code was sold on criminal forums in February 2024 โ€” the likely foundation for RansomHub's build. The FBI, CISA, and DC3 issued joint advisory AA24-242A on August 29, 2024, citing at least 210 confirmed victims across every major US critical infrastructure sector. By the time of its shutdown, victim counts had surged well past that baseline. RansomHub's explosive growth was driven by an industry-leading 90% affiliate revenue share, which drew the most experienced operators displaced from the simultaneous disruptions of LockBit (February 2024 law enforcement action) and ALPHV/BlackCat (March 2024 exit scam). Its April 2025 infrastructure shutdown remains unexplained โ€” possible causes include law enforcement pressure, internal conflict, or voluntary migration; DragonForce publicly claimed RansomHub "moved to their infrastructure," a claim disputed by multiple researchers.

Tradecraft

  • RaaS model with 90% affiliate revenue share โ€” the highest payout in the ransomware ecosystem; affiliates also permitted to negotiate with victims directly, without operator oversight.
  • Initial access: spear-phishing, exploitation of internet-facing vulnerabilities (see CVEs below), password spraying, and credential reuse from infostealer markets and dark-web credential dumps.
  • Exploited CVEs: CVE-2023-3519 (Citrix ADC/Gateway NetScaler), CVE-2023-27997 (Fortinet FortiOS SSL VPN), CVE-2023-46604 (Apache ActiveMQ RCE), CVE-2024-1709 (ConnectWise ScreenConnect auth bypass), CVE-2024-3400 (Palo Alto PAN-OS), CVE-2023-4966 (Citrix Bleed), CVE-2022-47966 (ManageEngine).
  • Lateral movement: PsExec, AnyDesk, ConnectWise ScreenConnect, Atera RMM, and standard Windows admin tooling.
  • Defense evasion: BYOVD (bring-your-own-vulnerable-driver) to disable EDR; log clearing; obfuscated scripts; disabling Windows Defender and AV via WMI.
  • Encryption: Curve25519 key exchange + AES-256 file encryption; intermittent encryption โ€” encrypts 0x100000-byte chunks and skips the following 0x200000 bytes, maximising speed while complicating full-volume recovery. Both Windows and Linux/ESXi variants deployed.
  • Double extortion: data exfiltrated before encryption; staged on a Tor-based DLS with 3 to 90-day payment deadlines, set by the individual affiliate.
  • CIS-exclusion clause included in affiliate guidelines.
  • Evil Corp affiliate (confirmed July 2024): Microsoft MSTIC reported that Manatee Tempest (Evil Corp), operating via SocGholish infections, deployed RansomHub post-compromise from at least July 2024. This creates OFAC/US Treasury sanctions exposure for any ransom negotiation or payment linked to those affiliate campaigns.

Notable victims

  • Change Healthcare (US; healthcare IT/claims processing; Febโ€“Apr 2024) โ€” ALPHV/BlackCat conducted the initial attack; their affiliate "Notchy" then partnered with RansomHub to publish 4 TB of stolen data after ALPHV exit-scammed him. 190 million Americans' health data stolen; $22M ransom paid to ALPHV (not RansomHub); UnitedHealth reported $872M in incident response costs. โ€” BleepingComputer ยท Kaspersky
  • Christie's (UK; major international auction house; May 2024) โ€” Attack timed to coincide with Christie's flagship spring auctions; ~500,000 client records exfiltrated and published after refusal to pay ransom. โ€” BleepingComputer
  • Patelco Credit Union (US; financial/California; Jun 2024) โ€” 726,000 members' PII (names, SSNs, dates of birth, driving licence numbers, email addresses) exfiltrated; prolonged system outage for direct deposit and bill pay services. โ€” BleepingComputer
  • Halliburton (US; global oilfield services; Aug 2024) โ€” IT systems taken offline; $35 million in confirmed losses (disclosed in SEC filing); data exfiltrated and published. โ€” SecurityWeek
  • City of Coppell, Texas (US; government; Nov 2024) โ€” City Wi-Fi, court operations, and library services disrupted. โ€” The Hacker News

Assessment

RansomHub's arc โ€” from launch to #1 global ransomware in under a year, then abrupt shutdown โ€” is the defining ransomware story of 2024. Its 90% affiliate cut was a market-disrupting move that concentrated the most experienced ransomware operators in a single platform, amplifying its reach far beyond what its small core team could have managed. The Evil Corp affiliate connection adds a sanctions dimension that distinguishes RansomHub from purely criminal operations: any payment to an Evil Corp-affiliated campaign implicates OFAC's Russia/Evil Corp sanctions list. Its April 2025 shutdown caused a redistribution event that directly powered Qilin's and DragonForce's subsequent growth โ€” making its collapse as significant as its rise. As of June 2026, Qilin is the dominant successor platform, averaging 90โ€“113 victims/month and maintaining the top global ransomware position for five straight months. VanHelsing, a second RaaS launched by former RansomHub affiliates, emerged in early 2025 as a separate downstream group. DragonForce publicly claimed it absorbed RansomHub infrastructure and affiliates; RansomHub publicly denied joining DragonForce. RansomHub's spokesperson "Koley" accused DragonForce of sabotage and alleged cooperation with law enforcement. VanHelsing (second RaaS launched by former RansomHub affiliates) is also inactive after its encryptor builder source code was leaked to RAMP by a disgruntled former developer. The true cause of the April 2025 shutdown โ€” law enforcement pressure, internal conflict, or voluntary migration โ€” remains unconfirmed.

As of September 2026, RansomHub shows 0 victim claims since its April 2025 shutdown (842 total historically) and remains dormant for 17+ months. Qilin holds rank 1 globally (YTD 546 victims, L3M 335, ~140/month pace) with The Gentlemen at rank 2 (YTD 335) โ€” both absorbed significant portions of the RansomHub affiliate base. DragonForce updated affiliate vetting requirements on RAMP in July 2026 (pre-acquired access + proof of exfiltrated data required before onboarding). The 90% affiliate cut that made RansomHub exceptional is now mirrored by both leading successors; the structural innovation has been normalised into the market. No credible reporting indicates a RansomHub revival is imminent as of September 2026. If RansomHub or a successor brand resurfaces, expect rapid re-aggregation of its former affiliate base given the unmatched revenue-share model that originally drove its growth.

Sources

๐Ÿ—‚๏ธ Attacks & victims

All disclosed victims attributed to this actor, newest first.

No attacks recorded yet.


โ† All threat actors ยท Full victim database โ†’