Skip to main content
Mallory
3 malware families

RansomHub

Also known asRansomHubSpoiled Scorpius

RansomHub is a ransomware-as-a-service (RaaS) operation that emerged in February 2024 and rapidly became one of the most active ransomware brands of 2024. It is also referred to as Spoiled Scorpius. Reporting in the provided content describes RansomHub as the volume leader in 2024 with 801 victims in 322 days, and as having absorbed many displaced operators after the disruption of LockBit and the collapse or exit scam of ALPHV/BlackCat. Multiple sources in the content state that RansomHub became dormant or ceased operations in early 2025, with dormancy noted since April 2025, and that affiliates subsequently migrated to other groups including Qilin and DragonForce. RansomHub operated an affiliate-based model with favorable terms for affiliates. ESET states it advertised on the Russian-speaking RAMP forum on February 2, 2024, offered affiliates direct receipt of ransom payments, a 90% revenue share, and support for Windows, Linux, and ESXi encryptors. The same reporting says its rules prohibited attacks against the Commonwealth of Independent States, Cuba, North Korea, and China. ESET further states that its encryptor was built from repurposed Knight source code and that its builder generated password-protected encryptors requiring a unique 64-character password for execution. On June 21, 2024, it reportedly tightened affiliate rules and required a US$5,000 deposit. The content links RansomHub to development and maintenance of the custom EDR killer EDRKillShifter, introduced to affiliates in May 2024 and later improved in June 2024. EDRKillShifter is described as using BYOVD techniques with known vulnerable drivers. ESET also reports tooling and affiliate overlaps between RansomHub, Play, Medusa, and BianLian, and attributes a cross-brand affiliate cluster called QuadSwitcher to intrusions involving RansomHub tooling. The content also notes use of mixed intrusion vectors such as callback phishing and voice phishing, and broader ransomware tradecraft associated with affiliates includes reconnaissance, credential abuse, lateral movement, and data exfiltration. Targets mentioned in the content span multiple sectors and geographies, including healthcare, government, manufacturing, legal, technology, finance, and business services. The healthcare sector is especially prominent in the supplied reporting: Trellix states RansomHub’s affiliate model enabled some of the most damaging healthcare attacks in 2025, and other reporting attributes or associates RansomHub with incidents involving Change Healthcare, MediSecure, and possibly Harvest through an affiliate. In the Change Healthcare case, the content states that by mid-April 2024 an aggrieved ALPHV affiliate formed RansomHub, retained data stolen from Change Healthcare, and attempted a second extortion against UnitedHealth. The content also notes claims that RansomHub stole 4 TB of Change Healthcare data and threatened publication. The content further associates RansomHub with collaboration or overlap involving other criminal ecosystems. Several sources state that Scattered Spider partnered with Russian ransomware gangs including RansomHub, and one report says some high-profile DragonForce-linked attacks involved actors formerly associated with RansomHub operations. Another source says DragonForce seemingly took over and later shut down RansomHub’s operation after infighting in April 2025. Known aliases and related naming in the provided content: RansomHub, Spoiled Scorpius.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

15 of 15 tactics62 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0042
Resource Development
2 techniques
T1587
Develop Capabilities
T1587.001
Malware
T1588
Obtain Capabilities
T1588.002
Tool
TA0001
Initial Access
4 techniques
T1078×2
Valid Accounts
T1133
External Remote Services
T1190×3
Exploit Public-Facing Application
T1566
Phishing
T1566.004
Spearphishing Voice
TA0002
Execution
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.007
JavaScript
T1204×2
User Execution
TA0003
Persistence
5 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1078×2
Valid Accounts
T1112
Modify Registry
T1133
External Remote Services
T1505
Server Software Component
TA0004
Privilege Escalation
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1068×3
Exploitation for Privilege Escalation
T1078×2
Valid Accounts
TA0005
Stealth
3 techniques
T1078×2
Valid Accounts
T1480
Execution Guardrails
T1497
Virtualization/Sandbox Evasion
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0006
Credential Access
5 techniques
T1003×2
OS Credential Dumping
T1187
Forced Authentication
T1552
Unsecured Credentials
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
8 techniques
T1033
System Owner/User Discovery
T1046
Network Service Discovery
T1057
Process Discovery
T1082
System Information Discovery
T1083
File and Directory Discovery
T1135
Network Share Discovery
T1482
Domain Trust Discovery
T1497
Virtualization/Sandbox Evasion
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001×2
Remote Desktop Protocol
T1021.002
SMB/Windows Admin Shares
TA0009
Collection
3 techniques
T1005
Data from Local System
T1074
Data Staged
T1213×2
Data from Information Repositories
TA0011
Command and Control
3 techniques
T1090
Proxy
T1090.003
Multi-hop Proxy
T1105×2
Ingress Tool Transfer
T1219
Remote Access Tools
TA0010
Exfiltration
5 techniques
T1020×2
Automated Exfiltration
T1041×4
Exfiltration Over C2 Channel
T1048×2
Exfiltration Over Alternative Protocol
T1537
Transfer Data to Cloud Account
T1567×7
Exfiltration Over Web Service
T1567.002×2
Exfiltration to Cloud Storage
TA0040
Impact
3 techniques
T1485
Data Destruction
T1486×23
Data Encrypted for Impact
T1657×5
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping49

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

RansomHub | Mallory