RansomHouse is a financially motivated cyber extortion and ransomware operation that emerged in late 2021. Known aliases include Jolly Scorpius, Ransom House, and related naming variants. The group initially distinguished itself by promoting an extortion-only model centered on data theft and public shaming of victims rather than file encryption, portraying itself as a "professional mediator" that exposes poor security practices. Over time, it evolved into a more conventional ransomware actor and has been associated with cryptographic lockers, including the Mario ESXi ransomware family, which has been linked to Babuk-derived code used against VMware ESXi environments. RansomHouse has targeted organizations across a wide range of sectors, including healthcare, government, retail, manufacturing, technology, cultural institutions, and critical infrastructure. Reported victims and claimed intrusions span hospitals and healthcare providers, cybersecurity vendors, automotive and commercial businesses, ticketing and cultural services, and public-sector entities. The group has also been associated with attacks affecting virtualized enterprise infrastructure and with incidents involving large-scale data exfiltration. Operationally, RansomHouse is best characterized as a data-theft-and-extortion actor that later incorporated encryption in at least some intrusions. It commonly seeks payment in exchange for suppressing publication or deleting stolen data rather than focusing solely on decryption. The group operates a leak site to pressure victims and has used staged proof disclosures and negotiation pressure tactics before full publication. Reporting has linked it to exploitation of exposed services, weak credentials, phishing, vulnerable remote access pathways, and opportunistic exploitation of known vulnerabilities, including cases where it may have leveraged high-profile edge-device flaws. RansomHouse has shown interest in VMware ESXi and other virtualized environments. Mario ESXi, associated with the group, shares code lineage with leaked Babuk source code, illustrating RansomHouse’s use or adaptation of existing ransomware tradecraft. The group has also been linked to tooling for both Windows and Linux environments and has been observed in intrusions where endpoint defense evasion played a role. Telemetry has placed RansomHouse intrusions alongside use of commercial EDR-killer tooling, indicating that affiliates or operators may disable security products prior to ransomware deployment or data theft. The group appears to operate within the broader ransomware affiliate ecosystem rather than as a purely standalone malware developer. It has been discussed alongside other major ransomware actors, and some reporting has suggested possible overlaps or loose links with other extortion brands, though such relationships are not consistently established at high confidence. RansomHouse is widely regarded as a criminal, not state-sponsored, threat actor. Overall, RansomHouse represents the evolution of modern ransomware from encryption-centric attacks toward hybrid extortion operations that combine credential abuse, intrusion into enterprise infrastructure, data exfiltration, leak-site coercion, and selective use of encryptors. Its activity demonstrates the convergence of pure extortion, virtualization-focused ransomware, and commercially sourced defense-evasion tooling in contemporary financially motivated intrusion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Fidelity Services Group.
Ransomware/extortion group reported targeting Trellix.
Conducting a ransomware attack resulting in a data breach against Karl Chevrolet in the United States.
Claimed responsibility for the cyberattack against Mission Community Hospital and stated that it exfiltrated approximately 2.5 TB of data containing sensitive patient information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.