DETECTO/ThreatDossier
DashboardPricingThreatsRun Free ScanSign In
DETECTO/ThreatDossier

Security intelligence for MSPs, consultants, and businesses. Find breached credentials, compliance gaps, and exposed infrastructure before attackers do.

Product

  • Scan a Domain
  • Pricing
  • Dashboard
  • Sign In

Resources

  • Threat Intelligence
  • Ransomware Groups

Legal

  • Privacy Policy
  • Terms of Service

© 2026 DETECTO. All rights reserved.

Threats/Groups/RansomHub

RansomHub

Inactive

ransomhub

First seen: 2024-02-10 20:10:13.609178Total victims: 844

The group emerged in mid-February 2024 and has already listed several organizations as alleged victims of their attacks, resulting from extortion through encryption and data leaks.<br> <br> The announcement of the sale of the new Ransomware-as-a-Service (RaaS) by RansomHub was published on one of the Russian-origin forums used by cybercrime to advertise malicious services, known as RAMP4U (or RAMP). A user with the nickname and persona of 'koley' announced the affiliate program on February 2, 2024.<br> <br> In the new RaaS announcement, it was mentioned that the money laundering operation of the paid ransoms is the responsibility of the affiliate. This means that all communication and sending of the decryptor to the victim are done through chat. The split of this RaaS would be 90% of the value for the affiliate and 10% for the developer, who in this case would be the persona of Koley.<br> <br> Furthermore, according to the publication, the ransomware payload is written in Golang language, uses the asymmetric algorithm based on x25519, and encryption algorithms AES256, ChaCha20, and xChaCha20, standing out for its speed. The encryption is obfuscated using AST.<br> <br> The payload would support network propagation and encryption of data both in secure and local mode. According to Koley, the ransomware is designed to operate on platforms such as Windows, Linux, and ESXi, as well as other architectures such as ARM and MIPS.<br> <br> As pointed out by the panel and already highlighted by the intelligence team, Koley stated that the panel uses a .onion domain, allowing the affiliate to organize and manage targets and chat rooms, view access logs, automatically respond when offline, and create private blog pages.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

0Total Victims
0Countries Targeted
0Sectors Targeted
0Avg Attacks/Month

Activity Timelinelast 24 months

Top Targeted Sectors

Top Targeted Countries

Recent Victimsshowing 50 of 844

NameCountrySectorDate
intellioan.comUSNot Found2025-03-31 23:21:00.788113
jackpotjunction.comUSHospitality and Tourism2025-03-31 23:19:21.968112
europtec.comDETechnology2025-03-31 21:40:34.981836
delta-life.comDENot Found2025-03-31 21:38:49.040361
www.assisi.nlNLHealthcare2025-03-29 21:26:21.414613
phaus.us&phakr.com&phabodysystems.comUSNot Found2025-03-28 21:40:30.002028
www.bassi.itITTechnology2025-03-28 18:50:56.516144
www.allmilmoe.comDEManufacturing2025-03-28 00:12:30.966656
brattenelectrictn.com—Manufacturing2025-03-27 15:11:21.075760
www.hongthongrice.comTHAgriculture and Food Production2025-03-26 22:27:11.597019
www.fkm-elemente.deDEManufacturing2025-03-26 22:25:19.664777
conterra.comDETechnology2025-03-26 16:28:51.508765
www.DSelectrical.com—Construction2025-03-26 07:16:49.536952
www.carolinaac.comUSConsumer Services2025-03-25 15:03:10.813244
www.garbinc.comUSManufacturing2025-03-25 15:01:19.696361
www.mododoc.comUSConsumer Services2025-03-25 14:58:47.609793
www.argentosc.comARNot Found2025-03-25 14:56:55.036191
www.ripplejunction.comUSConsumer Services2025-03-25 14:54:47.620466
www.creativelogisticservices.com—Transportation/Logistics2025-03-25 14:53:19.307244
www.afnigc.caCAPublic Sector2025-03-25 14:51:37.031549
www.cormidom.com.doDOManufacturing2025-03-25 14:49:18.471792
www.lions-online.orgDENot Found2025-03-25 14:47:09.130052
www.solidworld.itITTechnology2025-03-24 21:49:35.579486
www.s3s.com—Not Found2025-03-24 21:47:59.139190
www.rivaldt.comBRTechnology2025-03-24 21:46:41.901858
OMLTD.CO.JPJPNot Found2025-03-24 21:45:11.534642
technicare.comUSTechnology2025-03-24 21:43:41.402320
cisd.orgUSEducation2025-03-24 21:42:06.531000
mnm.huHUTechnology2025-03-24 21:40:34.178274
texascompressionservices.comUSManufacturing2025-03-24 21:39:19.385368
www.exemplar.com—Not Found2025-03-24 20:46:52.458163
www.solventacentroamerica.comGTManufacturing2025-03-24 18:06:50.010060
gbsn.com.brBRTechnology2025-03-21 22:04:51.255975
www.scpautomation.comCAManufacturing2025-03-21 19:06:15.355507
www.gestionquintessence.comCAFinancial Services2025-03-21 19:04:36.166927
www.engines.man.euEUManufacturing2025-03-21 19:02:46.651416
www.abmenviro.caCAManufacturing2025-03-21 19:00:38.474074
www.accessfinanceonline.comUSFinancial Services2025-03-21 18:59:09.170501
www.ahmadiyya.caCANot Found2025-03-21 18:57:25.137523
www.elizajennings.orgUSHealthcare2025-03-21 18:55:41.937006
www.sinkdirect.comUSConsumer Services2025-03-21 18:53:54.089615
www.broadmoormethodist.orgUSEducation2025-03-21 18:52:02.720546
www.parklandmanufacturing.com—Manufacturing2025-03-21 18:51:35.054835
www.solinst.comCAManufacturing2025-03-21 18:49:37.967399
www.allstarhealthcaresolutions.comUSHealthcare2025-03-21 18:47:57.796177
www.njcalwe.com—Not Found2025-03-21 18:45:43.875603
www.gcsnet.com—Technology2025-03-21 18:43:53.678963
www.core-1.com—Technology2025-03-21 18:42:17.662554
www.esquirebrands.comUSConsumer Services2025-03-21 18:40:37.741319
www.avalonapparel.comUSManufacturing2025-03-21 18:38:58.059125

Data from ransomware.live