RansomHub

RansomHub — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

RansomHubConfidence: High

Ransomware (RaaS)

Motivation: Financial

1Attributed Breaches
HighAttribution Confidence
Ransomware (RaaS)Actor Type

Overview

Emerged in February 2024 and quickly became a major extortion brand. CISA describes its activity as data theft, encryption, and leak-based pressure against global organizations under an affiliate-plus-leak-site model.

Tactics, Targeting & TTPs

Model: affiliates plus leak site. Targeting: global enterprise.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation