RansomHub Ransomware Group Strikes 210 Victims in Key Industries

Published:

spot_img

Recent Surge in Ransomware Attacks Linked to RansomHub Group and Evolution of Extortion Tactics

The U.S. government has identified a new ransomware group, RansomHub, that has targeted at least 210 victims across various sectors since its emergence in February 2024. Known for its ransomware-as-a-service model, RansomHub has attracted high-profile affiliates from other prominent variants such as LockBit and ALPHV.

According to ZeroFox, RansomHub’s activity has been on an upward trajectory, with the group accounting for approximately 2% of all ransomware attacks in Q1 2024, rising to 14.2% in Q3. The group employs the double extortion model, exfiltrating data and encrypting systems to extort victims.

RansomHub gains initial access to victim environments by exploiting known security vulnerabilities in various devices, followed by affiliates conducting reconnaissance and network scanning using tools like AngryIPScanner and Nmap. The group also disarms antivirus software to evade detection.

One notable aspect of RansomHub attacks is the use of intermittent encryption to speed up the process, with data exfiltration observed through various methods. The rise of RansomHub comes amidst a broader evolution in ransomware attacks, moving towards complex extortion strategies like triple and quadruple extortion schemes.

The lucrative nature of ransomware-as-a-service models has led to a surge in new variants, prompting even Iranian nation-state actors to collaborate with known groups for a share of illicit proceeds. The evolving landscape of ransomware threats underscores the need for robust cybersecurity measures to protect against such attacks.

spot_img

Related articles

Recent articles

Experts Warn: A Major Cybersecurity Breach in Healthcare is Inevitable

Rising Cybersecurity Threats in Healthcare: A Looming Crisis The Stark Reality of Cyber Incidents Experts in the healthcare field are sounding the alarm on cybersecurity threats,...

Iranian and Egyptian Foreign Ministers Discuss Key Issues in Phone Call

Iran and Egypt Celebrate Eid al-Adha with Diplomatic Dialogue A Warm Exchange of Greetings In a significant diplomatic interaction, Iranian Foreign Minister Seyed Abbas Araghchi and...

Malicious Browser Extensions Infect 722 Users in Latin America Since Early 2025

Emerging Cyber Threat: Malicious Extension Targets Brazilian Users Cybersecurity experts have recently uncovered a concerning campaign aimed at users in Brazil, which has been ongoing...

Searchlight Cyber Aids U.S. Government in Dismantling BidenCash Dark Web Marketplace

U.S. Law Enforcement Takes Down BidenCash Dark Web Marketplace Overview of the Operation In a significant law enforcement effort announced by the U.S. Department of Justice,...