#RansomHub
New Blog! Tracking Adversaries: EvilCorp, the RansomHub affiliate

blog.bushidotoken.net/2025/04/trac...
Tracking Adversaries: EvilCorp, the RansomHub affiliate
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
April 2, 2025 at 4:08 PM
A trip into #ransomware gangs: #RansomHub, affils and the rival ones.

The role of OSINT, research and in-depth analysis gives a pitch look at the life of a threat actor.

@ransomnews.online @sonoclaudio.ransomnews.online @fedtalk.bsky.social
Shifting the sands of RansomHub’s EDRKillShifter
ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play.
www.welivesecurity.com
April 16, 2025 at 4:19 AM
There's a ransomware group named DragonForce going around hacking its rivals.

After Mamona and BlackLock, the group has now hacked RansomHub—a major RaaS platform and one of the most active groups today.
April 5, 2025 at 11:11 PM
Esta vez es el Instituto Nacional de Investigación y Tecnología Agraria y Alimentaria el que es señalado en Darknet como victima de un ataque de ransomware, reinvindicado por el grupo Ransomhub
El Instituto , dependiente del MInisterio de Ciencia, fue atacado hace 15 días
December 10, 2024 at 8:32 PM
A new Endpoint Detection and Response (EDR) killer that is considered to be the evolution of 'EDRKillShifter,' developed by RansomHub, has been observed in attacks by eight different ransomware gangs.
New EDR killer tool used by eight different ransomware groups
A new Endpoint Detection and Response (EDR) killer that is considered to be the evolution of 'EDRKillShifter,' developed by RansomHub, has been observed in attacks by eight different ransomware gangs.
www.bleepingcomputer.com
August 7, 2025 at 5:58 PM
Podcast: risky.biz/RBNEWS388/
Newsletter: risky.biz/risky-bullet...

-It's probably not a good idea to pay RansomHub
-Insight Partners discloses hack
-Cyberattack hits Ecuador parliament
-OpenSSH patches MitM bug
-Monero zero-day awaits patch
-Cloudflare blocked in Spain on the weekends
February 19, 2025 at 9:36 AM
Ransomhub didn’t hack DragonForce, not sure where that claim has come from.
May 19, 2025 at 2:09 PM
#ESETresearch discovered previously unknown links between the #RansomHub, #Medusa, #BianLian, and #Play ransomware gangs, and leveraged #EDRKillShifter to learn more about RansomHub’s affiliates. @SCrow357 www.welivesecurity.com/en/eset-rese... 1/7
March 26, 2025 at 4:02 PM
#Grohe AG von #Ransomware-Attacke betroffen

"Die Grohe AG zählt zu den bekanntesten deutschen Herstellern von Armaturen und Sanitärprodukten. Die berüchtigte Ransomware-Bande #Ransomhub listet das Unternehmen nun als Opfer auf ihrer Darknet-Seite..."
www.csoonline.com/article/3808...
Grohe AG von Ransomware-Attacke betroffen
Die Cyber-Bande Ransomhub erpresst die Grohe AG mit gestohlenen Daten.
www.csoonline.com
January 31, 2025 at 12:34 PM
Apple contractors and assemblers are getting hacked left and right

cybernews.com/security/lux...
Vision Pro & iPhone schematics at risk: Attackers claim access to Luxshare designs
RansomHub ransomware gang breached Luxshare, Apple's key iPhone assembler, threatening to leak confidential 3D models, circuit designs for Apple, Nvidia and LG.
cybernews.com
January 20, 2026 at 2:14 PM
RansomHub Evolves To Attack Windows, ESXi, Linux and FreeBSD Operating Systems
RansomHub Evolves To Attack Windows, ESXi, Linux and FreeBSD Operating Systems
cybersecuritynews.com
February 17, 2025 at 1:34 PM
🇨🇭 Infoguard détecte une backdoor Python cachée chez DragonForce. La transition vers RaaS (LockBit, RansomHub) complexifie l'attribution et la défense. 🐍🔒 [lire]
April 14, 2026 at 5:56 AM
🚨🚨🇲🇽Government of Mexico Has Been Claimed a Victim to RansomHub Ransomware
darkwebinformer.com/government-o...
Government of Mexico Has Been Claimed a Victim to RansomHub Ransomware
Government of Mexico Has Been Claimed a Victim to RansomHub Ransomware
darkwebinformer.com
November 15, 2024 at 5:55 PM
Lot’s of rumors floating around about RansomHub pulling an exit scam and affiliates scrambling to try to get paid.

Who knew you couldn’t trust a ransomware group named after a porn site?
a woman is smiling and saying `` who woulda thought ? ''
ALT: a woman is smiling and saying `` who woulda thought ? ''
media.tenor.com
April 14, 2025 at 1:36 PM
Il gruppo #hellcat chiese a Schneider Electric un pagamento in #baguette (125k dollari).

#ransomhub si farà pagare in gioielli? In caso, chiedo un brillocco da mettere al mio braccialetto 🦄
𝗔𝗰𝘁𝗼𝗿: #ransomhub
𝗩𝗶𝗰𝘁𝗶𝗺: Giorgio Visconti SPA | giorgiovisconti.it
𝗖𝗼𝘂𝗻𝘁𝗿𝘆: Italy 🇮🇹
𝗦𝗮𝗺𝗽𝗹𝗲: yes
𝗘𝘅𝗳𝗶𝗹𝘁𝗿𝗮𝘁𝗲𝗱 𝗱𝗮𝘁𝗮: 40.00 GB
𝗗𝗲𝗮𝗱𝗹𝗶𝗻𝗲: December 10, 2024

🔗 ransomfeed.it/index.php?pa...

@sonoclaudio.rfeed.it @signorina37.rfeed.it
#ransomfeed #security #infosec
December 7, 2024 at 7:42 PM
November 19, 2024 at 6:28 AM
RansomHub ransomware uses new Betruger ‘multi-function’ backdoor

Security researchers have linked a new backdoor dubbed Betruger, deployed in several recent ransomware attacks, to an affiliate of the RansomHub operation.

www.bleepingcomputer.com/news/securit...

#cybersecuritytips #CyberSecurity
RansomHub ransomware uses new Betruger ‘multi-function’ backdoor
Security researchers have linked a new backdoor dubbed Betruger, deployed in several recent ransomware attacks, to an affiliate of the RansomHub operation.
www.bleepingcomputer.com
March 24, 2025 at 9:33 AM
New Blog! 👀

In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub.

🔗 www.sans.org/blog/evoluti...
October 6, 2025 at 6:04 PM
🚨Cyberattack Alert ‼️

🇪🇸Spain - J'hayber

RansomHub hacking group claims to have breached J'hayber.

Allegedly, 329 GB of data were exfiltrated.
Ransom deadline: 19th March 2025.
March 17, 2025 at 5:42 PM
Unfortunately, while much of the US is off this week, ransomware attacks continue unabated.

via @jgreig.bsky.social
RansomHub gang says it broke into networks of Texas city, Minneapolis agency
The RansomHub cybercrime operation took credit for publicly reported cyberattacks on the Coppell, Texas, government and the citywide parks agency for Minneapolis.
therecord.media
November 27, 2024 at 1:22 PM