Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Ransomware

RansomHub explained: the post-LockBit consolidator

Ransomnews Research TeamBy Ransomnews Research TeamMay 3, 2026No Comments3 Mins Read902 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
A hub-shaped logo placeholder with affiliate figure silhouettes feeding into it carrying lock icons
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

RansomHub appeared in early 2024 and within a year became the largest active ransomware-as-a-service program by claim count, filling much of the void left by the LockBit takedown and the ALPHV exit-scam. In 2026 they remain at the top of the leaderboard. Here’s how they got there and what they look like operationally.

The affiliate-friendly structure

RansomHub’s pitch to affiliates was specific and well-timed. Where ALPHV exit-scammed an affiliate by withholding a multi-million-dollar payout in early 2024, RansomHub launched with a 90/10 affiliate split (against the typical 70/30 or 80/20) and a structure where the affiliate received the ransom payment directly and forwarded the operator’s cut, rather than the other way around. The trust-architecture move was deliberate. Affiliates who’d been burned moved their pipelines onto RansomHub’s encryptor within weeks.

The technical capability

The encryptor itself is competent rather than novel. Cross-platform support (Windows, Linux, ESXi). The expected combination of strong encryption (Curve25519 + ChaCha20), shadow-copy deletion, and selective skipping of system folders to keep the OS bootable for the ransom note. The privilege-escalation tooling, lateral-movement scripts, and disabling-of-security-tools scripts are essentially the standard 2024-2025 affiliate toolkit.

Where they invest more than typical: leak-site and victim-management tooling. The affiliate portal is genuinely well-designed for the operator’s UX. That investment shows up in the operator’s ability to handle high volume without operational mistakes.

Notable victim profile

RansomHub’s victim profile across 2025 covers most sectors. Healthcare disproportionately represented. Multiple municipal-government incidents. Several large logistics and shipping operators. The tendency is toward mid-market enterprise targets where the ransom can be priced in low millions and the victim has the cash to pay if cornered.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

The 2025 healthcare-sector incidents in particular drew sustained attention from US authorities and were a major contributor to the HHS cybersecurity guidance updates of late 2025.

The Scattered Spider connection

A meaningful share of RansomHub’s high-profile incidents have been attributed to Scattered Spider operators using RansomHub’s encryptor. The arrangement appears stable and ongoing. The implication: defending against RansomHub specifically requires defending against Scattered Spider’s TTPs (help-desk social engineering, SIM-swap), not just generic ransomware-affiliate TTPs.

Detection and defence priorities

Initial-access vectors observed across RansomHub incidents are unsurprising: Citrix and Ivanti edge appliance exploits, stolen credentials from stealer logs, social-engineering against IT help desks. The defensive priority list is therefore the standard one: edge-appliance patching, MFA hardening, identity-monitoring for impossible-travel and risk-based authentication, EDR coverage on every Windows host that touches the network, and offline backups verified through quarterly restore tests.

What’s next

RansomHub’s structural position is strong but not invulnerable. The same affiliate-friendliness that built them up means affiliates can leave fast if a competitor offers better terms. Several mid-tier operators are now offering 95/5 splits. Watch for affiliate migration through 2026, the operator at the top of the leaderboard a year from now may be a different brand entirely, populated by the same operatives.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleScattered Spider in 2026: still the SIM-swap kings
Next Article Stealer log forensics: tracing infections back to the user
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Interlock: the drive-by ransomware crew CISA flagged

July 20, 2026

SafePay: the centralised crew that skipped affiliates

July 20, 2026

INC Ransom: the RaaS that wins by mastering the basics

July 20, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.