- First observed: February 2024
- Believed origin: A rebrand/spinoff of the Knight ransomware; Russian-based or Russian-friendly
- Model: Ransomware-as-a-Service (RaaS)
- Status: Active
Origin
Researchers generally trace RansomHub's code, rather than its brand, back further than February 2024. Investment firm and threat analyst Bitsight’s technical write-up found that, “the group is widely believed to be a spinoff of the Knight ransomware, which itself originated from the Cyclops group, with technical analysis showing strong code similarities between the two - RansomHub is primarily written in Golang and uses Gobfuscate for obfuscation.”
On the question of nationality, the clues point toward Russia, though nothing is confirmed. BitSight noted, “While it is difficult to definitively say where the group is based, many clues point to it being Russian-based or Russian-friendly, and the homepage of its data leak site explicitly states it prohibits attacks on ‘CIS, Cuba, North Korea, and China.’"
Furthermore, when BlackCat pulled its exit scam after Change Healthcare paid a $22 million ransom in early 2024, the affiliate who had actually carried out the attack, known online as "Notchy," was left with stolen healthcare data with no way to monetize it through the group that had betrayed them. Threat intelligence firm SentinelOne's analysis on the group's rise noted what happened next, “RansomHub operations were first observed in February 2024, and since then the group drew heavily on its ability to recruit operators from other, sometimes imploding, extortion operations - when ALPHV collapsed, multiple affiliates migrated to RansomHub, hoping to monetize their stolen data through the new platform.”
Threat intelligence firm Forescout documented the announcement, “RansomHub was announced as a new ransomware-as-a-service affiliate program on the well-known RAMP cybercriminal forum on February 2, by a user going by ‘koley.’” The forum post, according to Forescout's analysis, laid out the group's offering, its encryption malware "the locker," an affiliate negotiation panel, and the terms for joining the program.
Read also:
Extorting the same victim twice
Forescout's timeline of the events noted that, “RansomHub started leaking Change Healthcare files on April 15, and extorted the company a second time, claiming that the original ransom payment had not gone to the right people.” This left Change Healthcare facing a second extortion demand for data that had, in theory, already been paid for once.
Investment firm and threat analyst Bitsight connected the dots on the affiliate's likely motivation, noting, “A BlackCat affiliate who allegedly stole the Change Healthcare data has since claimed they were cheated out of their share of the ransom, and it is believed the recent ransom demand from RansomHub affiliates may be tied to the affiliate's efforts to recoup their lost profit.” The fallout for the broader healthcare industry was severe enough that UnitedHealth Group had to step in financially, Bitsight noted, “UnitedHealth Group provided temporary financial assistance totaling $4.7 billion to healthcare providers affected by the breach.”
The Hacker News reported that a now-former admin of the BlackCat group was quoted as saying, "A re-branding is pending," supporting the theory that RansomHub could be a continuation of BlackCat under a new name, or a new group for the affiliates BlackCat had scammed out of their cut of the ransom.
Learn more: Going deeper: The Change Healthcare attack
A business model designed to poach talent
RansomHub built a recruitment pitch specifically for affiliates affected by other groups' broken promises. Where BlackCat had reportedly promised affiliates up to 90% of ransom payments and then simply not paid, RansomHub built trust into its payment systems. BitSight's analysis of the group's operations explained the mechanism, noting that, “unlike traditional ransomware models where the core group controls ransom payments, RansomHub allows its affiliates to manage their own cryptocurrency wallets and receive payments directly from victims, remitting only a 10% commission back to the core group.”
This trust-first pitch worked. SentinelOne's tracking found that, “the primary operators behind RansomHub openly recruited affiliates from other ransomware operations via their various communication channels, including their data leak site, forum posts, and Telegram.” Group-IB's 2025 threat assessment of the group found the group did not only recruit BlackCat members, noting, “After launching its affiliate program in February 2024, RansomHub recruited former Scattered Spider group members as well as ex-Conti and ex-REvil operators, offering a RaaS platform that enabled even lower-skilled cybercriminals to launch sophisticated attacks.”
Tactics
Trend Micro's threat profile explained the approach, “RansomHub quickly gained notoriety for its "big game hunting" tactic, preying on victims more likely to pay large ransoms to mitigate business downtime, and specifically targeting cloud storage backups and misconfigured Amazon S3 instances to threaten backup providers with data leaks by exploiting the trust between providers and their clients.”
FAQs
What is ransomware-as-a-service (RaaS)?
It's a business model where a group develops and maintains ransomware tools and infrastructure, then leases access to affiliates who carry out the actual attacks in exchange for a cut of the ransom.
What is "big game hunting" in ransomware attacks?
It's a targeting strategy where attackers deliberately go after large organizations with financial resources because they're more likely to pay a large ransom quickly to avoid costly downtime.
How do ransomware groups gain initial access to a victim's network?
Common entry points include phishing emails, stolen or weak credentials, unpatched software vulnerabilities, and misconfigured remote access tools.
What is "double extortion" in ransomware attacks?
It's a tactic where attackers both encrypt a victim's systems and steal their data beforehand, threatening to publish the stolen data even if the victim restores systems from backup without paying.
