RansomHub is a financially motivated ransomware-as-a-service (RaaS) operation that emerged in early 2024 and became one of the most prominent criminal ransomware brands of 2024–2025. It is tracked under aliases including Spoiled Scorpius and various naming variants such as RansomHub ransomware group, RansomHub affiliates, and RansomHub ransomware actors. The operation uses an affiliate model in which core operators provide ransomware tooling and supporting infrastructure while affiliates conduct intrusions, lateral movement, data theft, and extortion. RansomHub has been associated with broad opportunistic targeting across sectors and geographies, consistent with major RaaS ecosystems. Reporting links its affiliates and partners to compromises involving enterprise environments, including organizations reached through exposed remote services, remote monitoring and management software, compromised credentials, and malware-delivered initial access. Observed access pathways and enabling ecosystems tied to RansomHub activity include abuse of Splashtop for remote access and persistence, use of SocGholish/FakeUpdates as an initial access conduit in some intrusion chains, and collaboration or overlap with actors such as Scattered Spider. Operationally, RansomHub intrusions have been associated with common big-game ransomware tradecraft: credential theft, privilege escalation, defense evasion, lateral movement, and double extortion. Affiliates have been observed using legitimate administrative tools and dual-use utilities such as PsExec for remote execution and lateral movement, alongside NirSoft credential-recovery tools and Mimikatz-style credential theft in broader ransomware playbooks that also include RansomHub. Linux-focused reporting also associates RansomHub campaigns with post-compromise privilege escalation via CVE-2024-1086 and persistence through newly created systemd services. The group has also been linked to deployment of Betruger by affiliates. A notable feature of the RansomHub ecosystem is its investment in centralized affiliate tooling for defense evasion. The group developed an in-house endpoint security killer known as EDRKillShifter and made it available to affiliates through its affiliate panel, indicating a comparatively mature service model in which operators supplied specialized anti-EDR capability rather than leaving all tooling to affiliates. RansomHub appears to have maintained relationships, overlaps, or ecosystem ties with several other major ransomware actors. Public reporting has associated it with Scattered Spider activity and with broader ransomware-network interactions involving DragonForce, Qilin, LockBit, ALPHV/BlackCat, Everest, BlackLock, and DEVMAN. Some reporting indicates that disruption or closure of RansomHub in April 2025 contributed to affiliate migration toward rival operations, especially Qilin, while other reporting describes DragonForce as taking over or partnering with RansomHub infrastructure. These developments suggest that RansomHub functioned as an important node in the mid-2020s ransomware affiliate marketplace. By 2025, RansomHub was widely regarded as a leading RaaS threat, but its operational continuity appears to have been disrupted in April 2025. Subsequent reporting describes the group as going offline or shutting down, with affiliates and associated actors dispersing to other ransomware brands. Despite that apparent decline, RansomHub remains significant for its role in shaping affiliate-enabled ransomware operations, its use of centralized anti-EDR tooling, and its connections to other major criminal ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only in the actor index/TTP section without substantive discussion.
Referenced as an example ransomware group documented using systemd service persistence and CVE-2024-1086 for post-compromise privilege escalation.
Referenced as another ransomware group using the same PsExec and NirSoft tradecraft to compromise enterprise networks.
Mentioned only as a ransomware operation that previously partnered with Scattered Spider.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.