RansomHub Ransomware Group Strikes 210 Victims in Key Industries

Published:

spot_img

Recent Surge in Ransomware Attacks Linked to RansomHub Group and Evolution of Extortion Tactics

The U.S. government has identified a new ransomware group, RansomHub, that has targeted at least 210 victims across various sectors since its emergence in February 2024. Known for its ransomware-as-a-service model, RansomHub has attracted high-profile affiliates from other prominent variants such as LockBit and ALPHV.

According to ZeroFox, RansomHub’s activity has been on an upward trajectory, with the group accounting for approximately 2% of all ransomware attacks in Q1 2024, rising to 14.2% in Q3. The group employs the double extortion model, exfiltrating data and encrypting systems to extort victims.

RansomHub gains initial access to victim environments by exploiting known security vulnerabilities in various devices, followed by affiliates conducting reconnaissance and network scanning using tools like AngryIPScanner and Nmap. The group also disarms antivirus software to evade detection.

One notable aspect of RansomHub attacks is the use of intermittent encryption to speed up the process, with data exfiltration observed through various methods. The rise of RansomHub comes amidst a broader evolution in ransomware attacks, moving towards complex extortion strategies like triple and quadruple extortion schemes.

The lucrative nature of ransomware-as-a-service models has led to a surge in new variants, prompting even Iranian nation-state actors to collaborate with known groups for a share of illicit proceeds. The evolving landscape of ransomware threats underscores the need for robust cybersecurity measures to protect against such attacks.

spot_img

Related articles

Recent articles

WhatsApp Launches Beta of Scam Alert Feature to Identify Suspicious Messages

WhatsApp has initiated a limited beta rollout of its Scam Alert feature, designed to identify suspicious messages from non-contacts using an on-device machine learning...

Ransomware Recovery Challenges: 34% of ANZ Organizations Still Opt to Pay Ransom Despite Uncertain Outcomes

Research published by Commvault reveals that 34% of organizations in Australia and New Zealand that experienced a ransomware attack opted to pay the ransom....

OpenAI Flags Astra Model for Critical Cybersecurity Risks, Halting Development

OpenAI has raised alarms regarding its forthcoming AI model, Astra, which may pose a ‘critical’ cybersecurity risk. This assessment has led the company to...

Redomiciling to Dubai does not exempt firms from MiCA obligations, warns Relm official

Insurance gaps in director liability, custody, and wallets often surface only after crypto firms relocate, warns Relm’s global distribution chief. Dubai has become a focal...