RansomHub, also known as Spoiled Scorpius, was a ransomware-as-a-service operation active from early 2024 until its apparent closure or retirement in April 2025. The operation recruited affiliates and supplied them with ransomware tooling, including endpoint-security-disabling capabilities. RansomHub ransomware targeted Windows, Linux, and VMware ESXi environments and was implemented in Go and C++. The group conducted encryption and data-theft extortion operations, maintained a leak site, and publicly released victim data when extortion demands were not met. RansomHub was associated with the secondary extortion of Change Healthcare after an affiliate formerly associated with ALPHV/BlackCat retained stolen data. The group also claimed an attack against Bologna FC. Affiliates have used credential-harvesting utilities, PsExec for lateral movement, Linux privilege-escalation exploits, persistence mechanisms, and PoorTry/BurntCigar to impair endpoint defenses before encryption. Some former ALPHV/BlackCat affiliates joined RansomHub, but available evidence does not conclusively establish RansomHub as an ALPHV/BlackCat rebrand.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in connection with affiliates deploying a Python backdoor showing signs of AI-assisted development; described as now DragonForce.
Claimed a ransomware attack against Bologna FC and published stolen data after the club refused to pay the ransom.
A ransom group joined by a former BlackCat affiliate that attempted a second extortion of UHG using retained stolen data.
Referenced as one of the ransomware operations DevMan previously affiliated with before launching its own RaaS program.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.