Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
RansomHub was a ransomware-as-a-service operation that emerged in February 2024 and rapidly became the most prolific RaaS brand of 2024, absorbing experienced affiliates displaced by the law-enforcement disruptions of LockBit (Operation Cronos) and ALPHV/BlackCat. It ran an affiliate-friendly, double-extortion model and, per the CISA #StopRansomware advisory AA24-242A, had encrypted or exfiltrated data from at least 210 victims across critical-infrastructure sectors by August 2024. Its infrastructure went dark on 1 April 2025, after which its affiliates dispersed, chiefly to Qilin and DragonForce. RansomHub is now widely assessed as defunct.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
RansomHub first appeared on the ransomware scene in February 2024. Multiple vendors (Symantec, ESET, Group-IB, BleepingComputer/CSO reporting) identified strong code and web-panel similarities to the earlier Knight ransomware (itself a rebrand of Cyclops), and Group-IB assessed that RansomHub's operators most likely acquired the Knight/Cyclops ransomware and web-application source code rather than being a straight continuation of the same crew. This lineage gave RansomHub a mature, cross-platform (Windows, Linux, ESXi) encryptor from launch.
RansomHub's rise was inseparable from the 2024 collapse of the two dominant RaaS brands. The February 2024 LockBit takedown (Operation Cronos) and the March 2024 ALPHV/BlackCat exit scam left large numbers of skilled affiliates without a platform. RansomHub launched an aggressive, affiliate-friendly partnership program on forums such as RAMP, offering unusually favorable terms — reporting indicates affiliates kept roughly 90% of ransom proceeds and, atypically, collected payment directly before forwarding the operator's cut, which reduced affiliate fear of being stiffed. A pivotal moment was the Change Healthcare fallout: after ALPHV appeared to withhold the reported $22M ransom from its affiliate 'Notchy,' Notchy and other former ALPHV affiliates moved to RansomHub, which then separately extorted Change Healthcare's parent using the stolen data. These dynamics propelled RansomHub to the top of the 2024 ransomware leaderboards, averaging (per CISA) at least three victims per day in mid-2024 across water/wastewater, IT, government, healthcare, financial services, critical manufacturing, and other sectors.
+39 more relationships — see the relationships browser.
On 1 April 2025 RansomHub's infrastructure and data-leak site went offline abruptly. Group-IB and others reported that the outage drove affiliates to migrate, with Qilin's leak-site disclosures roughly doubling in the following weeks and DragonForce publicly claiming to have taken over RansomHub's infrastructure. The exact cause of the shutdown (voluntary exit, internal dispute, or interference by a rival/DragonForce) is not definitively established in public reporting and should be treated as low-to-medium confidence. As of this writing RansomHub has not resumed operations and is assessed as defunct, though some 2025 reporting noted claims it 'planned to return' — an unverified claim.
MENA relevance: The RaqibCTI tags (UAE, Saudi Arabia, Egypt, Lebanon) are MIXED and mostly weakly supported. Lebanon has the strongest basis: a Lebanon-based oil-and-gas infrastructure fabricator (reported as TETCO) was named as a RansomHub victim in vendor reporting, so Lebanon reflects at least one plausible named claim. UAE, Saudi Arabia, and Egypt appear to rest on regional aggregate ransomware statistics and leak-site/aggregator (ransomware.live-style) counts that lump many groups together rather than confirmed, independently corroborated RansomHub intrusions in those countries; treat them as UNVERIFIED leak-site/aggregate claims pending a named victim and primary-source corroboration. Overall confidence in the MENA targeting picture is low-to-medium and none of these should be presented as confirmed RansomHub compromises without a specific victim citation.
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.