Ransomware Group intelligence
Ransomhub
InactiveTrack Ransomhub with 843 published victims and 3 known leak locations in a single intelligence view.
Overview
Ransomhub is tracked by Breach House as a ransomware group with 843 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 26m ago | fpwwt67hm3mkt6hdavkfyqi42oo3vkaggvjj4kxdr2ivsbzyka5yr2qd.onion |
| Leak location 2 | Onion service | Down checked 26m ago | ransomgxjnwmu5ceqwo2jrjssxpoicolmgismfpnslaixg3pgpe5qcad.onion |
| Leak location 1 | Onion service | Down checked 26m ago | ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion |
Top Activity Sectors (17)
- Not identified 194
- Communication / Marketing 194
- Services 123
- Healthcare / Pharma 50
- Manufacturing / Engineering 40
- Finance / Legal / Insurance 39
- Construction / Real Estate 37
- IT 36
- Education 28
- Energy 23
- Public Sector 19
- Retail / E-commerce 18
- Hospitality / Food & Beverage / Tourism 13
- Transportation / Travel / Logistics 12
- Agriculture / Food 11
- Telecommunications 3
- NGOs / Associations 2
Typical Attacks (21)
▼How Ransomhub typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via RansomHub.
-
T1059.001 PowerShell Execution
What they do: RansomHub can use PowerShell to delete volume shadow copies.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: RansomHub can use `cmd.exe` to execute multiple commands on infected hosts.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: RansomHub has an encrypted configuration file.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: RansomHub has the ability to self-delete.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: RansomHub can use a provided passphrase to decrypt its configuration file.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1480 Execution Guardrails Stealth
What they do: RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
What they do: RansomHub can sleep for a set number of minutes before beginning execution.
What that means: Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: RansomHub can delete events from the Security, System, and Application logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1688 Safe Mode Boot Defense Impairment
What they do: RansomHub can reboot targeted systems into Safe Mode prior to encryption.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1018 Remote System Discovery Discovery
What they do: RansomHub can enumerate all accessible machines from the infected system.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: RansomHub can retrieve information about virtual machines.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: RansomHub has the ability to only encrypt specific files.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: RansomHub has the ability to target specific network shares for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1090 Proxy Command and Control
What they do: RansomHub can use a proxy to connect to remote SFTP servers.
What that means: Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
-
T1486 Data Encrypted for Impact Impact
What they do: RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: RansomHub has the ability to terminate specified services.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: RansomHub has used `vssadmin.exe` to delete volume shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (25)
▼Software Ransomhub has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_[id]_4.txt
We are the RansomHub. Your company Servers are locked and Data has been taken to our servers. This is serious. Good news: - your server system and data will be restored by our Decryption Tool; - for now, your data is secured and safely stored on our server; - nobody in the world is aware about the data leak from your company except you and RansomHub team; FAQs: Who we are? - Normal Browser Links: https://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/ - Tor Browser Links: http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/ Want to go to authorities for protection? - Seeking their help will only make the situation worse,They will try to prevent you from negotiating with us, because the negotiations will make them look incompetent,After the incident report is handed over to the government department, you will be fined <This will be a huge amount,Read more about the GDRP legislation:https://en.wikipedia.org/wiki/General_Data_Protection_Regulation>,The government uses your fine to reward them.And you will not get anything, and except you and your company, the rest of the people will forget what happened!!!!! Think you can handle it without us by decrypting your servers and data using some IT Solution from third-party "specialists"? - they will only make significant damage to all of your data; every encrypted file will be corrupted forever. Only our Decryption Tool will make decryption guaranteed; Don't go to recovery companies, they are essentially just middlemen who will make money off you and cheat you. - We are well aware of cases where recovery companies tell you that the ransom price is xxx dollars, but in fact they secretly negotiate with us for xxx dollars, so they earn xxx dollars from you. If you approached us directly without intermediaries you would pay 5 times less, that is xxx dollars. Think your partner IT Recovery Company will do files restoration? - no they will not do restoration, only take 3-4 weeks for nothing; besides all of your data is on our servers and we can publish it at any time; as well as send the info about the data breach from your company servers to your key partners and clients, competitors, media and youtubers, etc. Those actions from our side towards your company will have irreversible negative consequences for your business reputation. You don't care in any case, because you just don't want to pay? - We will make you business stop forever by using all of our experience to make your partners, clients, employees and whoever cooperates with your company change their minds by having no choice but to stay away from your company. As a result, in midterm you will have to close your business. So lets get straight to the point. What do we offer in exchange on your payment: - decryption and restoration of all your systems and data within 24 hours with guarantee; - never inform anyone about the data breach out from your company; - after data decryption and system restoration, we will delete all of your data from our servers forever; - provide valuable advising on your company IT protection so no one can attack your again. Now, in order to start negotiations, you need to do the following: - install and run 'Tor Browser' from https://www.torproject.org/download/ - use 'Tor Browser' open http://dd4djzr2ywfcox3zfvpkpyh3b657hsdwpwv5cfkmdfde2lr3fpz6spad.onion/ - enter your Client ID: There will be no bad news for your company after successful negotiations for both sides. But there will be plenty of those bad news if case of failed negotiations, so don't think about how to avoid it. Just focus on negotiations, payment and decryption to make all of your problems solved by our specialists within 1 day after payment received: servers and data restored, everything will work good as new. ************************************************
readme_[id]_3.txt
We are the RansomHub. Your company Servers are locked and Data has been taken to our servers. This is serious. Good news: - your server system and data will be restored by our Decryption Tool; - for now, your data is secured and safely stored on our server; - nobody in the world is aware about the data leak from your company except you and RansomHub team; FAQs: Who we are? - Normal Browser Links: https://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/ - Tor Browser Links: http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/ Want to go to authorities for protection? - Seeking their help will only make the situation worse,They will try to prevent you from negotiating with us, because the negotiations will make them look incompetent,After the incident report is handed over to the government department, you will be fined <This will be a huge amount,Read more about the GDRP legislation:https://en.wikipedia.org/wiki/General_Data_Protection_Regulation>,The government uses your fine to reward them.And you will not get anything, and except you and your company, the rest of the people will forget what happened!!!!! Think you can handle it without us by decrypting your servers and data using some IT Solution from third-party "specialists"? - they will only make significant damage to all of your data; every encrypted file will be corrupted forever. Only our Decryption Tool will make decryption guaranteed; Think your partner IT Recovery Company will do files restoration? - no they will not do restoration, only take 3-4 weeks for nothing; besides all of your data is on our servers and we can publish it at any time; as well as send the info about the data breach from your company servers to your key partners and clients, competitors, media and youtubers, etc. Those actions from our side towards your company will have irreversible negative consequences for your business reputation. You don't care in any case, because you just don't want to pay? - We will make you business stop forever by using all of our experience to make your partners, clients, employees and whoever cooperates with your company change their minds by having no choice but to stay away from your company. As a result, in midterm you will have to close your business. So lets get straight to the point. What do we offer in exchange on your payment: - decryption and restoration of all your systems and data within 24 hours with guarantee; - never inform anyone about the data breach out from your company; - after data decryption and system restoration, we will delete all of your data from your servers forever; - provide valuable advising on your company IT protection so no one can attack your again. Now, in order to start negotiations, you need to do the following: - install and run 'Tor Browser' from https://www.torproject.org/download/ - use 'Tor Browser' open http://pod4gkypkd6kykwoht3kioehhpoh4k75ybdfoe6q7hqbphrd77b32jqd.onion/ - enter your Client ID: [snip] There will be no bad news for your company after successful negotiations for both sides. But there will be plenty of those bad news if case of failed negotiations, so don't think about how to avoid it. Just focus on negotiations, payment and decryption to make all of your problems solved by our specialists within 1 day after payment received: servers and data restored, everything will work good as new. ************************************************
readme_[id]_2.txt
Hello!
Visit our Blog:
Tor Browser Links:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/
Links for normal browser:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/
>>> Your data is stolen and encrypted.
If you don't pay the ransom, the data will be published on our TOR darknet sites. Keep in mind that once your data appears on our leak site, it could be bought by your competitors at any second, so don't hesitate for a long time. The sooner you pay the ransom, the sooner your company will be safe.
>>> If you have an external or cloud backup; what happens if you don’t agree with us?
All countries have their own PDPL (Personal Data Protection Law) regulations. In the event that you do not agree with us, information pertaining to your companies and the data of your company’s customers will be published on the internet, and the respective country’s personal data usage authority will be informed. Moreover, confidential data related to your company will be shared with potential competitors through email and social media. You can be sure that you will incur damages far exceeding the amount we are requesting from you should you decide not to agree with us.
>>> How to contact with us?
- Install and run 'Tor Browser' from https://www.torproject.org/download/
- Go to http://cki3klxqycazagx3r5prae3nmfvxmwa34beknr3il4uf76vxd76akqid.onion/
- Log in using the Client ID: [snip]
>>> WARNING
DO NOT MODIFY ENCRYPTED FILES YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
This link (TOR) is your private blog link. Right now it is only available to you but in 72 hours if you don't get in touch it will be published on our platform and will be seen by thousands of journalists: ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/[snip]/
readme_[id].txt
Hello!
Visit our Blog:
Tor Browser Links:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/
Links for normal browser:
http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion.ly/
>>> Your data is stolen and encrypted.
If you don't pay the ransom, the data will be published on our TOR darknet sites. Keep in mind that once your data appears on our leak site, it could be bought by your competitors at any second, so don't hesitate for a long time. The sooner you pay the ransom, the sooner your company will be safe.
>>> If you have an external or cloud backup; what happens if you don’t agree with us?
All countries have their own PDPL (Personal Data Protection Law) regulations. In the event that you do not agree with us, information pertaining to your companies and the data of your company’s customers will be published on the internet, and the respective country’s personal data usage authority will be informed. Moreover, confidential data related to your company will be shared with potential competitors through email and social media. You can be sure that you will incur damages far exceeding the amount we are requesting from you should you decide not to agree with us.
>>> How to contact with us?
- Install and run 'Tor Browser' from https://www.torproject.org/download/
- Go to http://davtdavm734bl4hkr3sr4dvfzpdzuzei2zrcor4vte4a3xuok2rxcmyd.onion/
- Log in using the Client ID: [snip]
>>> WARNING
DO NOT MODIFY ENCRYPTED FILES YOURSELF.
DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.
YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (843)
Search, filter and paginate the victim timeline for Ransomhub. Showing 801–843 of 843.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | CORIENT id12124 View details | United States | Other | ||
|
Visits: 74 Data Size: 30GB Published: False |
|||||
| Ransomware | [Published]Constelacion Savings and Credit Society id12123 View details | El Salvador | Finance / Legal / Insurance | ||
|
Visits: 19418 Data Size: 497GB Published: TrueDownload: http://ransomgxjnwmu5ceqwo2jrjssxpoicolmgismfpnslaixg3pgpe5qcad.onion/www.constelacion.com.sv/ |
|||||
| Ransomware | HARMAN - CYNC SOLUTIONS client id12110 View details | United States | Services | ||
|
Visits: 93 Data Size: 82Gb Published: False |
|||||
| Ransomware | CYNC SOLUTIONS - The unexpected target. id12073 View details | United States | Services | ||
|
Visits: 46 Data Size: 5Tb Published: False |
|||||
| Ransomware | Mercatino S.r.l. https://www.mercatinousato.com id11716 View details | Italy | Other | ||
|
Visits: 616 Data Size: 1.5TB Published: False |
|||||
| Ransomware | FábricaInfo id11713 View details | Brazil | Other | ||
|
Visits: 137 Data Size: 11.6 GiB Published: False |
|||||
| Ransomware | Mercatino https://www.mercatinousato.com id11711 View details | Italy | Other | ||
|
Visits: 87 Data Size: 1.5TB Published: False |
|||||
| Ransomware | Empresa de energía del Bajo Putumayo id11699 View details | Colombia | Communication / Marketing | ||
|
Visits: 46 Data Size: 20,2 GB Published: False |
|||||
| Ransomware | Change HealthCare - OPTUM Group - United HealthCare Group - FOR SALE id11697 View details | United States | Healthcare / Pharma | ||
|
Visits: 9992 Data Size: 4TB Published: False |
|||||
| Ransomware | Grupo Cuevas id11689 View details | Spain | Other | ||
|
Visits: 71 Data Size: 26GB Published: False |
|||||
| Ransomware | Robeson County Sheriff's Office id11631 View details | United States | Public Sector | ||
|
Visits: 66 Data Size: 1.1 TB Published: False |
|||||
| Ransomware | Baca County Feedyard, Inc id11565 View details | United States | Public Sector | ||
|
Visits: 2 Data Size: 220GB Published: False |
|||||
| Ransomware | Skyway Coach Lines and Shuttle Services -- skywaycoach.ca id11557 View details | Canada | Services | ||
|
Visits: 41 Data Size: 60GB Published: False |
|||||
| Ransomware | PHARMACY ETTORE FLORIO SNC - Online Pharmacy Italy id11552 View details | Italy | Healthcare / Pharma | ||
|
Visits: 33 Data Size: 200Gb Published: False |
|||||
| Ransomware | Change HealthCare - OPTUM Group - United HealthCare Group id11539 View details | United States | Healthcare / Pharma | ||
|
Visits: 38 Data Size: 4TB Published: False |
|||||
| Ransomware | Carrozzeria Aretusa srl id11533 View details | Italy | Other | ||
|
Visits: 16 Data Size: 90GB Published: False |
|||||
| Ransomware | HCI Systems, Inc. id11532 View details | United States | Services | ||
|
Visits: 20 Data Size: 500Gb Published: False |
|||||
| Ransomware | Better Accounting Solutions id11528 View details | United States | Finance / Legal / Insurance | ||
|
Visits: 62 Data Size: 200 GB Published: False |
|||||
| Ransomware | Agencia Host id11520 View details | Brazil | Other | ||
|
Visits: 118 Data Size: 8 GB Published: False |
|||||
| Ransomware | Constelacion Savings and Credit Society id11511 View details | El Salvador | Finance / Legal / Insurance | ||
|
Visits: 15 Data Size: 497GB Published: False |
|||||
| Ransomware | Avant IT Norway id11437 View details | Norway | Other | ||
|
Visits: 27 Data Size: 7G Published: False |
|||||
| Ransomware | Woodsboro ISD id11369 View details | United States | Other | ||
|
Visits: 5 Data Size: 45GB Published: False |
|||||
| Ransomware | Power Generation Engineering and Services Company (PGESCo) - pgesco.com id11343 View details | Egypt | Manufacturing / Engineering | ||
|
Visits: 170 Data Size: 8 Tb Crypted Published: False |
|||||
| Ransomware | Industrial de Alimentos EYL SA id11335 View details | Honduras | Manufacturing / Engineering | ||
|
Visits: 104 Data Size: 17 GB Published: False |
|||||
| Ransomware | La Pastina id11325 View details | Brazil | Other | ||
|
Visits: 50 Data Size: 6GB Published: False |
|||||
| Ransomware | McKim & Creed id11216 View details | United States | Other | ||
|
Visits: 62 Data Size: 500+ GB Published: False |
|||||
| Ransomware | SBM & Co id11215 View details | United Kingdom | Other | ||
|
Visits: 355 Data Size: 200 GB Published: False |
|||||
| Ransomware | SBM & Co id11212 View details | United Kingdom | Other | ||
|
Visits: 4 Data Size: 200 GB Published: False |
|||||
| Ransomware | Kovra id11207 View details | Malaysia | Other | ||
|
Visits: 50 Data Size: 12GB Published: False |
|||||
| Ransomware | Computan id11163 View details | Canada | Other | ||
|
Visits: 93 Data Size: 72GB Published: False |
|||||
| Ransomware | Scadea Solutions id11155 View details | United States | Services | ||
|
Visits: 13 Data Size: 30GB Published: False |
|||||
| Ransomware | DVT id11153 View details | United Kingdom | IT | ||
|
Visits: 57 Data Size: 51GB Published: False |
|||||
| Ransomware | Rekamy id11152 View details | Malaysia | Other | ||
|
Visits: 3 Data Size: 42GB Published: False |
|||||
| Ransomware | go4kora id11151 View details | Tuvalu | Other | ||
|
Visits: 5 Data Size: 12GB Published: False |
|||||
| Ransomware | SIEA id11140 View details | Slovakia | Other | ||
|
Visits: 55 Data Size: 62GB Published: False |
|||||
| Ransomware | Hozzify id11139 View details | Colombia | Other | ||
|
Visits: 47 Data Size: 136GB Published: False |
|||||
| Ransomware | Merchant ID id11129 View details | Indonesia | Other | ||
|
Visits: 22 Data Size: 50GB Published: False |
|||||
| Ransomware | SP Mundi id11128 View details | Brazil | Other | ||
|
Visits: 33 Data Size: 8GB Published: False |
|||||
| Ransomware | Shooting House id11049 View details | Brazil | Other | ||
|
Visits: 41 Data Size: 60GB Published: False |
|||||
| Ransomware | Benthanh Group id11027 View details | Viet Nam | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Headwater Companies LLC id10983 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | AL SHEFA FARM id10965 View details | Romania | Agriculture / Food | ||
|
No additional victim description available. |
|||||
| Ransomware | YKP LTDA id10765 View details | Brazil | Services | ||
|
No additional victim description available. |
|||||