Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
RansomHouse is a financially motivated data-extortion and (later) ransomware operation that emerged in late 2021. It originally branded itself as a 'mediator' or professional-negotiation service that claims not to encrypt victim data, instead stealing files and coercing payment via a dedicated dark-web leak site. Over time it adopted encryption tooling associated with the White Rabbit and Mario/Mario ESXi families and built out automation (the MrAgent tool) for mass VMware ESXi deployment, evolving toward an affiliate/RaaS-style model.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
RansomHouse first surfaced in December 2021, with early public reporting tying it to an extortion of Canada's Saskatchewan Liquor and Gaming Authority (SLGA). From the outset the group cultivated an unusual self-presentation: rather than calling itself a ransomware gang, it framed its leak site as a 'professional mediators community' that helps victims 'audit' their own security, and it repeatedly claimed it does not encrypt data and holds no responsibility for the intrusions it profits from. In practice this positioned RansomHouse as a data-extortion operation that would exfiltrate data (sometimes from breaches carried out by others) and pressure victims through naming, shaming, and public data leaks.
Despite the 'we do not encrypt' branding, RansomHouse activity has been linked to actual ransomware tooling. Since early in its operations it has been alternately referred to as White Rabbit and Mario ESXi, and researchers observed ransom notes in which the actors identify themselves under one or more of these names. The group deployed the Mario encryptor across Windows, Linux, and VMware ESXi environments, and in 2024 Trellix documented a bespoke automation utility named MrAgent designed to run on ESXi hypervisors, disable host firewalls, and orchestrate ransomware deployment across many hypervisors simultaneously. Palo Alto Unit 42 also documented upgrades to the RansomHouse/Mario encryption scheme over time, indicating ongoing tooling development rather than a purely opportunistic reseller of leaked data.
+21 more relationships — see the relationships browser.
A notable analytic thread is the connection to the 8Base group, which appeared in 2023. Cyberint researchers ran the Natural Language Processing model Doc2Vec across ransom notes and leak-site language and reported roughly a 99% match between 8Base and RansomHouse notes, with near-identical leak-site wording. This raised the still-unresolved question of whether 8Base is an offshoot, an affiliate, or a copycat of RansomHouse. Because RansomHouse historically used a variety of ransomware sourced from dark markets rather than a single signature strain, definitive code-level attribution has been difficult, and the linguistic link should be treated as a strong-but-circumstantial indicator (medium confidence).
RansomHouse's best-known victims include semiconductor maker AMD, from whom the group claimed to have stolen roughly 450GB of data in 2022 (including a CSV listing of over 70,000 internal devices; AMD and the actors disputed the exact intrusion timeline around January 2022), and Colombian healthcare provider Keralty and its subsidiaries EPS Sanitas and Colsanitas, where the group claimed to have taken around 3TB of data in a late-2022 attack that disrupted care for millions of patients. The group has remained active into 2025 and 2026, with public leak-site trackers such as ransomware.live logging 200+ claimed victims across roughly four dozen countries and recent listings continuing into 2026 (e.g., victims in the US, Japan, China, and Europe). Its status is best described as active, though its exact organizational form (in-house crew vs. affiliate/RaaS platform) has shifted over its lifetime and is characterized differently across vendors.
MENA relevance: RansomHouse's public leak site lists a small number of MENA victims — in Saudi Arabia (e.g., United Lube Oil Company, listed ~Oct 2025; Fursan Travel, listed ~Oct 2024) and Egypt (e.g., Steel Corners Industrial Co. / Arkan, listed ~Dec 2025) — so the RaqibCTI 'Saudi Arabia' and 'Egypt' country tags do correspond to real leak-site listings rather than being wholly invented, but these are unverified extortion claims from the actor's own site and aggregators (ransomware.live), not independently confirmed compromises, and the region is a minor part of RansomHouse's overall, US/Europe/East-Asia-weighted victimology; treat the MENA tags as MIXED — genuine leak-site claims, low independent confirmation.