Unattributed financially motivated cybercrime group; no confirmed nation-state or named-crew attribution in public reporting. Cyberint used a Doc2Vec ransom-note comparison to identify a ~99% linguistic match between RansomHouse and the later 8Base group, suggesting affiliation, shared operators, or a copycat relationship, but the exact overlap remains unconfirmed. English is the primary operating language of the group's communications and leak site.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Core of the data-extortion model: operators manually harvest documents from Active Directory hosts, NAS storage and virtual-machine guests - 600 GB in the Resecurity case, 4.5 TB from a European hospital per Halcyon - before any encryption.
Resecurity documented a password-spraying campaign against the victim's Microsoft Exchange accounts from APAC residential proxies that compromised three employee mailboxes before the Mario/White Rabbit deployment.
The White Rabbit Windows encrypter used in RansomHouse-linked intrusions only runs when passed the correct command-line password (-p 'KissMe', Egregor-style), so the ~100 KB payload is inert in sandboxes and without operator input (Trend Micro Jan 2022).
Unit 42 (Dec 2025) found the upgraded Mario/MrAgent binaries padded with junk code and using dynamically sized, non-linear chunk processing to frustrate static analysis and signature matching.
MrAgent runs esxcli network firewall set --enabled false on every targeted ESXi host before deploying the encrypter (Trellix; Unit 42) - this RansomHouse behavior is the cited ESXi example in the ATT&CK technique entry.
MrAgent fingerprints each hypervisor on start with uname -a, esxcli network nic list and esxcli network ip interface ipv4 get, and reports running VMs back to C2 (Unit 42 Dec 2025; Trellix).
Resecurity observed stolen data staged to MEGA via Rclone alongside FTP in the White Rabbit/Mario intrusion; Halcyon lists MEGA.co.nz via MEGAsync/Rclone as RansomHouse's primary exfiltration destination.
MrAgent changes the hypervisor root password and kills non-root SSH sessions so administrators cannot intervene or recover during encryption (Trellix; Unit 42).
MrAgent stops the vCenter agent with /etc/init.d/vpxa stop and shuts down running VMs to release disk locks before Mario encrypts VMDK/VMEM/VSWP files (Unit 42; Trellix).
MrAgent rewrites the ESXi DCUI welcome message via esxcli system welcomemesg set to display the ransom notice on the hypervisor console (Trellix; Unit 42).
When RansomHouse does encrypt, it deploys Babuk-derived Mario ESXi (ChaCha20 + RSA-4096, .emario extension, 'How To Restore Your Files.txt' note, two-key sparse encryption in the 2025 upgrade) on hypervisors and White Rabbit on Windows (Unit 42; Trellix; Resecurity).
Extortion-first operation: victims are pressured via a Tor leak site, Telegram channels and media-coverage links, with data sold to other actors or published if unpaid; CISA AA24-241A maps the RansomHouse revenue-share arrangement with Iranian brokers to T1657.
Compromised Exchange mailbox and VPN credentials (Resecurity) and compromised RDS / third-party vendor accounts lacking MFA (Halcyon profile) are the recurring foothold; RansomHouse itself sells victims a report of the credentials and vulnerabilities used.
Resecurity (Dec 2023) traced a White Rabbit/Mario intrusion to an end-of-life Cisco ASA 5506-X AnyConnect VPN appliance used as the entry point; CISA AA24-241A lists T1133 for the broker access resold to RansomHouse.
RansomHouse's stated model is breaching networks via unpatched vulnerabilities (ThreatDown/Malwarebytes 2022); CISA AA24-241A names RansomHouse as a ransomware partner of Iranian access brokers exploiting Citrix NetScaler CVE-2023-3519, Check Point CVE-2024-24919, PAN-OS CVE-2024-3400 and Ivanti CVE
MrAgent operates from a root shell on ESXi and explicitly drops non-root SSH sessions to prevent interference during encryption (Trellix); Halcyon reports SSH root access to hypervisors as the path to datastore encryption.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside RansomHouse's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 9 techniques
App GovernanceT1562significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1078minimalConditional AccessT1110significantConditional AccessT1110.003significantID ProtectionT1110partialID ProtectionT1110.003partialIdentity Secure ScoreT1078minimalIdentity Secure ScoreT1110partialIdentity Secure ScoreT1110.003partialIdentity Secure ScoreT1531partialMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1110significantMultifactor AuthenticationT1110.003significantPrivileged Identity ManagementT1078minimalPasswordless AuthenticationT1110significantPasswordless AuthenticationT1110.003significantPasswordless AuthenticationT1531significantPassword PolicyT1078significantPassword PolicyT1110partialPassword PolicyT1110.003partialPassword ProtectionT1078partialPassword ProtectionT1110partialPassword ProtectionT1110.003partialRole Based Access ControlT1078minimalRole Based Access ControlT1562minimalAntimalwareT1027significantAudit SolutionsT1078partialAudit SolutionsT1562partialInformation ProtectionT1567significant
detect · 11 techniques
App GovernanceT1078significantApp GovernanceT1110significantApp GovernanceT1110.003significantApp GovernanceT1562significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1110significantAdvanced Threat HuntingT1110.003significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1110partialDefender for Cloud AppsT1110.003partialDefender for Cloud AppsT1133partialDefender for Cloud Apps
respond · 7 techniques
Automated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1567significantIncident ResponseT1078minimalIncident ResponseT1110minimalIncident ResponseT1110.003minimalIncident ResponseT1531minimalIncident ResponseT1562minimalQuarantine PoliciesT1027significantZero Hour Auto PurgeT1027significantConditional AccessT1078minimalID ProtectionT1110minimalID ProtectionT1110.003significant
Countermeasures · D3FEND
Defensive techniques that counter RansomHouse's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.