By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: RansomHub Ransomware Group Targets 210 Victims Across Critical Sectors
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > RansomHub Ransomware Group Targets 210 Victims Across Critical Sectors
Tech News

RansomHub Ransomware Group Targets 210 Victims Across Critical Sectors

By Viral Trending Content 6 Min Read
Share
SHARE
RansomHub Ransomware Group

Threat actors linked to the RansomHub ransomware group encrypted and exfiltrated data from at least 210 victims since its inception in February 2024, the U.S. government said.

The victims span various sectors, including water and wastewater, information technology, government services and facilities, healthcare and public health, emergency services, food and agriculture, financial services, commercial facilities, critical manufacturing, transportation, and communications critical infrastructure.

“RansomHub is a ransomware-as-a-service variant—formerly known as Cyclops and Knight—that has established itself as an efficient and successful service model (recently attracting high-profile affiliates from other prominent variants such as LockBit and ALPHV),” government agencies said.

A ransomware-as-a-service (RaaS) variant that’s a descendant of Cyclops and Knight, the e-crime operation has attracted high-profile affiliates from other prominent variants such as LockBit and ALPHV (aka BlackCat) following a recent wave of law enforcement actions.

ZeroFox, in an analysis published late last month, said RansomHub’s activity as a proportion of all ransomware activity observed by the cybersecurity vendor is on an upward trajectory, accounting for approximately 2% of all attacks in Q1 2024, 5.1% in Q2, and 14.2% so far in Q3.

Cybersecurity

“Approximately 34% of RansomHub attacks have targeted organizations in Europe, compared to 25% across the threat landscape,” the company noted.

The group is known to employ the double extortion model to exfiltrate data and encrypt systems in order to extort victims, who are urged to contact the operators via a unique .onion URL. Targeted companies who refuse to acquiesce to the ransom demand have their information published on the data leak site for anywhere between three to 90 days.

Initial access to victim environments is facilitated by exploiting known security vulnerabilities in Apache ActiveMQ (CVE-2023-46604), Atlassian Confluence Data Center and Server (CVE-2023-22515), Citrix ADC (CVE-2023-3519), F5 BIG-IP (CVE-2023-46747), Fortinet FortiOS (CVE-2023-27997), and Fortinet FortiClientEMS (CVE-2023-48788) devices, among others.

This step is succeeded by affiliates conducting reconnaissance and network scanning using programs like AngryIPScanner, Nmap, and other living-off-the-land (LotL) methods. RansomHub attacks further involve disarming antivirus software using custom tools to fly under the radar.

“Following initial access, RansomHub affiliates created user accounts for persistence, re-enabled disabled accounts, and used Mimikatz on Windows systems to gather credentials [T1003] and escalate privileges to SYSTEM,” the U.S. government advisory reads.

“Affiliates then moved laterally inside the network through methods including Remote Desktop Protocol (RDP), PsExec, AnyDesk, Connectwise, N-Able, Cobalt Strike, Metasploit, or other widely used command-and-control (C2) methods.”

Another notable aspect of RansomHub attacks is the use of intermittent encryption to speed up the process, with data exfiltration observed through tools such as PuTTY, Amazon AWS S3 buckets, HTTP POST requests, WinSCP, Rclone, Cobalt Strike, Metasploit, and other methods.

The development comes as Palo Alto Networks Unit 42 unpacked the tactics associated with the ShinyHunters ransomware, which it tracks as Bling Libra, highlighting its shift to extorting victims as opposed to their traditional tactic of selling or publishing stolen data. The threat actor first came to light in 2020.

“The group acquires legitimate credentials, sourced from public repositories, to gain initial access to an organization’s Amazon Web Services (AWS) environment,” security researchers Margaret Zimmermann and Chandni Vaya said.

“While the permissions associated with the compromised credentials limited the impact of the breach, Bling Libra infiltrated the organization’s AWS environment and conducted reconnaissance operations. The threat actor group used tools such as the Amazon Simple Storage Service (S3) Browser and WinSCP to gather information on S3 bucket configurations, access S3 objects and delete data.”

Cybersecurity

It also follows a significant evolution in ransomware attacks, which have moved beyond file encryption to employ complex, multi-faceted extortion strategies, even employing triple and quadruple extortion schemes, per SOCRadar.

“Triple extortion ups the ante, threatening additional means of disruption beyond encryption and exfiltration,” the company said.

“This might involve conducting a DDoS attack against the victim’s systems or extending direct threats to the victim’s clients, suppliers, or other associates to wreak further operational and reputational damage on those ultimately targeted in the extortion scheme.”

Quadruple extortion ups the ante by contacting third-parties that have business relationships with the victims and extorting them, or threatening victims to expose data from third-parties to heap further pressure on a victim to pay up.

The lucrative nature of RaaS models has fueled a surge in new ransomware variants like Allarich, Cronus, CyberVolk, Datablack, DeathGrip, Hawk Eye, and Insom. It has also led Iranian nation-state actors to collaborate with known groups like NoEscape, RansomHouse, and BlackCat in return for a cut of the illicit proceeds.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Meath’s Hanley Energy to be acquired by Jabil in $725m deal

VSDinside Launches MagTran M3 – The World’s First Fully Customizable Transparent Keyboard

Samsung Galaxy A17 5G Review: Sleek but Samey

Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly

AWS announces Fastnet, a dedicated high-capacity transatlantic cable connecting the U.S. and Ireland

TAGGED: critical infrastructure, Cyber Security, Cybercrime, Cybersecurity, data breach, Incident response, Internet, network security, Ransomware, Threat Intelligence, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article US seizes Venezuelan President Maduro's plane
Next Article Netanyahu pushes back against new pressure over Gaza and hostages: ‘No one will preach to me’
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

ZKsync price jumps above $0.06 with 87% weekly gains amid major token utility overhaul
Crypto
Bitcoin Struggles Around $100K As STH Losses Mount: SOPR Signals Pressure, Not Panic
Crypto
Meath’s Hanley Energy to be acquired by Jabil in $725m deal
Tech News
Swiss top court upholds conviction of four over ‘Kill Erdoğan’ banner at 2017 rally
World News
Europe gets its first stablecoin infrastructure ETP as Virtune lists on Nasdaq and Xetra
Crypto
Could Diageo shares be a value trap?
Business
Black Myth: Wukong is Still Untouchable a Year After Launch
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

ZKsync price jumps above $0.06 with 87% weekly gains amid major token utility overhaul

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
ZKsync price jumps above $0.06 with 87% weekly gains amid major token utility overhaul
November 6, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?