White Paper
THREAT PROFILE: Ransomhub Ransomware
RansomHub is a ransomware-as-a-service (RaaS) group first identified in 2024 that uses a double-extortion model, encrypting systems while exfiltrating sensitive data and threatening to publish it if ransom demands are not met. The group has frequently targeted organizations in manufacturing, construction, engineering, and other industrial sectors, where operational disruptions can have significant financial impact. This threat profile examines RansomHub’s targeted industries and geographic regions, known exploited vulnerabilities, associations with other cybercriminal groups, attack tools, and observed behaviors in Windows environments. It also reviews execution methods used during attacks and maps the group’s tactics, techniques, and procedures to the MITRE ATT&CK framework. By analyzing
