Software · OAK-S34 · ransomware
OAK-S34 — RansomHub ransomware
Description
RansomHub is the ransomware encryptor codebase and brand maintained by a Russian-speaking operator cohort from February 2024 onward, emerging in the post-Cronos / post-ALPHV-exit-scam landscape with a market-positioning explicitly designed to capture the high-tier affiliate diaspora from the disrupted competitor brands. The brand's Q2–Q4 2024 growth — from a February 2024 cold start to the top-by-leak-site-postings RaaS brand by H2 2024 — is the cleanest documented case in the modern RaaS sector of rapid market-share capture via affiliate-cohort absorption from disrupted predecessor brands, and is the principal reason RansomHub's emergence is widely treated as a structural rather than incremental event in the post-Cronos ransomware-sector trajectory.
The encryptor's distinguishing technical features include the Knight / Cyclops-class codebase derivation (partial source-code lineage to a 2023-era Russian-speaking-cohort encryptor, providing the developer-side technical substrate for the brand's rapid operational-launch capacity), a dual-language architecture across Windows and Linux/ESXi variants (Go and Rust components documented in different builds across 2024), aggressive partial-encryption mode for speed-versus-stealth tradeoff, and an affiliate-program structure with a 90/10 affiliate/operator split (publicly advertised on Russian-language criminal forums as the most affiliate-favourable split in the sector at the time of launch) — the low operator-cut was a deliberate market-positioning choice to attract the high-tier affiliate cohort displaced from ALPHV (which had run a 80/20-to-90/10 split itself before the exit-scam) and from LockBit (which had run a 80/20 split before Operation Cronos).
The CISA / FBI / MS-ISAC / HHS joint advisory AA24-242A of August 29, 2024 ([cisaaa24242a]) is the canonical confirmed-grade institutional-attribution document for the brand, documenting over 210 victim organisations through August 2024 and explicitly identifying RansomHub as having absorbed affiliates from ALPHV and LockBit following the disruption events that affected those brands earlier in 2024. The advisory's targeting of healthcare and public-health verticals as the priority concern reflects the post-Change-Healthcare regulatory-and-political-attention surface in U.S. healthcare cybersecurity, and the four-agency joint format (CISA / FBI / MS-ISAC / HHS) signals the same sector-priority architecture used for AA24-131A (Black Basta) following the May 2024 Ascension Health incident.
The family's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader post-Conti / post-ALPHV affiliate-cohort laundering pattern. The on-chain-side defining signature for RansomHub's 2024 trajectory is the wallet-cluster persistence (OAK-T8.001) connecting RansomHub-attributable affiliate clusters to prior ALPHV-attributable affiliate clusters — the same affiliate operators rotated wallet-funding patterns onto RansomHub-issued payment addresses while retaining the upstream-funding-source topology that anchored their ALPHV-era activity, producing one of the cleanest documented cases of cross-brand-affiliate-continuity-via-on-chain-wallet-cluster-tracking in the modern RaaS forensic record.
Observed examples
- Change Healthcare (post-March 2024 secondary leak). Following the ALPHV operators' exit-scam diversion of the ~$22M Change Healthcare ransom payment in early March 2024, the "Notchy" affiliate (the operator behind the Change Healthcare deployment under the ALPHV brand) re-published the stolen Change Healthcare data on the RansomHub leak site in April 2024, demanding a second ransom from UnitedHealth Group. The episode is the canonical worked example of post-exit-scam-affiliate-rotation as continuity tooling and the cleanest single-affiliate evidentiary chain for the ALPHV-to-RansomHub absorption pattern. Confirmed-grade per industry reporting and
[cisaaa24242a]cohort context. - Christie's auction house incident (May 2024). RansomHub-claimed deployment against Christie's during the spring 2024 auction season; data published on the RansomHub leak site after non-payment; one of the higher-profile financial-services-adjacent incidents of 2024. Confirmed-grade per Christie's own incident-disclosure and RansomHub leak-site posting.
- Frontier Communications incident (April 2024). RansomHub-claimed deployment against Frontier Communications, a major U.S. telecommunications provider; data published on the RansomHub leak site; one of the more-prominent 2024 telecommunications-sector incidents. Confirmed-grade per Frontier 8-K disclosure and RansomHub leak-site posting.
- Rite Aid incident (June 2024). RansomHub-claimed deployment against Rite Aid pharmacy chain; data published on the RansomHub leak site after non-payment; representative of the 2024 retail-pharmacy-sector incident pattern. Confirmed-grade per Rite Aid incident-disclosure.
- CISA AA24-242A campaign cohort (February–August 2024). The advisory documents over 210 named-and-unnamed RansomHub victim organisations across U.S. critical-infrastructure sectors with healthcare, water-and-wastewater, IT, government, and emergency-services verticals prominently called out. Confirmed-grade aggregate per
[cisaaa24242a]. - OAK on-chain example surface. The Change Healthcare secondary-leak episode of April 2024 is the strongest candidate for a future OAK example entry showing the OAK-S34-binary × cross-brand affiliate-rotation × T8.001 worked example, paired with the existing Change-Healthcare-on-chain-trace evidence base from OAK-S24 BlackCat / ALPHV. The structural framing would document the affiliate-side wallet-cluster continuity across the ALPHV-to-RansomHub brand-rotation as the on-chain attribution signature.
Detection / attribution signals
Defenders should treat RansomHub detection as a host-layer + on-chain-layer joint problem with the cross-brand-affiliate-continuity tracking at the OAK-T8.001 level as the principal forensic signature distinguishing post-ALPHV-rotation affiliates from independent emergence:
- Host-layer process-tree fingerprints — characteristic file-extension changes (random-string extensions appended to encrypted files, with per-affiliate-configurable patterns); ransom-note filenames (
README.txtper-folder); Windows-binary signature with partial structural similarities to the prior Knight / Cyclops codebase documented by Mandiant and Microsoft; Go-language and Rust-language signatures in different builds across 2024; partial-encryption mode signature; ESXi-variant invokes the standardesxcliVM-shutdown sequence shared across post-2022 RaaS brands. - Pre-encryption tradecraft — initial access via VPN-credential brute-force (against Cisco, Fortinet, Palo Alto, Citrix appliances), ZeroLogon (CVE-2020-1472) where unpatched, ConnectWise ScreenConnect vulnerabilities (CVE-2024-1709, CVE-2024-1708), and other commodity-RCE entry points; post-foothold deployment of Cobalt Strike (OAK-S37) and Sliver / Brute Ratel C2; credential theft via Mimikatz and the standard Russian-speaking-RaaS-cohort tooling; lateral movement via PsExec, WMI, and operator-bundled deployment scripts.
- Network-layer telemetry — Cobalt Strike post-exploitation deployment after VPN-credential or RCE foothold; data-exfiltration to operator-controlled cloud-storage staging (Mega.io, rclone-to-S3); leak-site negotiation-portal access patterns; RansomHub leak-site infrastructure operated continuously through 2024 with operator-side rotation onto multiple bulletproof-hosting providers documented.
- On-chain-layer signatures (the OAK-relevant signal — the load-bearing detection vector for RansomHub specifically) — RansomHub affiliate-controlled ransom-payment wallets exhibit common-funder cluster reuse (OAK-T8.001) with prior ALPHV-attributable affiliate clusters at a density unmatched by any independent-emergence RaaS brand, providing the principal forensic anchor for the post-ALPHV affiliate-absorption attribution work; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; the per-incident ransom volumes span the full small-to-large enterprise spectrum (the 90/10 affiliate split attracted both small-incident-high-cadence affiliates and large-incident-low-cadence affiliates), producing a heterogeneous on-chain signature relative to the more-uniform Akira pattern.
- CTI vendor coverage — Mandiant (RansomHub intrusion-set tracking and the Knight-derivative codebase attribution work), Microsoft Threat Intelligence (RansomHub / Storm-class tracking and the post-ALPHV affiliate-migration documentation), Sophos (sustained "State of Ransomware" reporting and the RansomHub-rapid-emergence analysis), Trend Micro (continuous version-by-version analysis), Recorded Future (Insikt Group sustained RansomHub-and-affiliate-migration reporting), Coveware (incident-response-side payment and negotiation-pattern reporting), Chainalysis and TRM Labs (on-chain affiliate-cluster cross-brand-continuity tracking — the load-bearing CTI surface for RansomHub specifically).
Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA24-242A and live CTI-vendor feeds named above.
Citations
[cisaaa24242a]— CISA / FBI / MS-ISAC / HHS joint advisory AA24-242A on RansomHub ransomware, August 29, 2024. (NEW citation — see summary.)[mandiantransomhub2024]— Mandiant RansomHub intrusion-set tracking and Knight-derivative codebase attribution. (NEW citation — see summary.)[microsoftransomhub2024]— Microsoft Threat Intelligence RansomHub / post-ALPHV-affiliate-migration analysis. (NEW citation — see summary.)[sophosransomhub2024]— Sophos RansomHub rapid-emergence and tradecraft analysis. (NEW citation — see summary.)[trendmicroransomhub2024]— Trend Micro RansomHub version-by-version analysis. (NEW citation — see summary.)[chainalysisransomhub2024]— Chainalysis RansomHub-attributable ransom-payment-volume tracking and post-ALPHV-affiliate-migration wallet-cluster analysis. (NEW citation — see summary.)[recordedfutureransomhub2024]— Recorded Future / Insikt Group sustained RansomHub-and-affiliate-migration reporting. (NEW citation — see summary.)[ofac2022garantex]— Treasury OFAC Garantex designation press release; broader Russian-speaking-RaaS-cohort laundering-venue context.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report; cross-family context for the RansomHub volume distribution and post-ALPHV market-share-capture.
Discussion
On the post-ALPHV-affiliate-absorption pattern as the central framing. OAK-S34's principal value as a Software entry is as the canonical worked example of rapid market-share capture via affiliate-cohort absorption from disrupted predecessor brands. The brand's February 2024 cold-start-to-H2-2024-top-by-leak-site-postings trajectory is the cleanest documented case of this pattern in the modern RaaS sector and is structurally distinct from the codebase-version-rotation continuity (LockBit), the codebase-derivative successor-brand continuity (Black Basta, Royal/BlackSuit), and the independent-operator emergence pattern (Akira). The 90/10 affiliate/operator split is the load-bearing market-positioning lever that enabled the absorption, and it provides a useful comparative reference for understanding the operator-side economic-incentive engineering that shapes affiliate-cohort migration patterns in the modern RaaS sector.
On the Change Healthcare secondary-leak episode as evidentiary anchor. The April 2024 Change Healthcare data re-publication on the RansomHub leak site by the "Notchy" affiliate is the cleanest single-affiliate evidentiary chain for the ALPHV-to-RansomHub absorption pattern — a single named affiliate, with documented prior-ALPHV-affiliation, executing a documented post-exit-scam rotation onto the RansomHub affiliate panel within weeks of the ALPHV dissolution, with the rotation visible in both the leak-site evidence and the on-chain wallet-cluster persistence at the OAK-T8.001 level. The episode anchors a substantial fraction of the post-ALPHV-affiliate-migration attribution work and is the principal evidentiary basis for the CISA AA24-242A advisory's explicit identification of RansomHub as an ALPHV-affiliate-absorber.
On predecessors at the codebase level. RansomHub's encryptor codebase shows partial structural similarities to the prior Knight / Cyclops-class encryptor (a 2023-era Russian-speaking-cohort encryptor that had been advertised for sale on Russian-language criminal forums), suggesting a purchased-or-licensed-source-code basis for the developer-side technical substrate. This pattern — a new operator cohort acquiring source code from a prior cohort to bootstrap the technical substrate of a new brand — is structurally distinct from the leaked-source-code-fork pattern (LockBit Green / Conti v3) and from the in-house-development pattern (ALPHV's clean Rust rewrite) and is one of several mechanisms through which RaaS encryptor codebases circulate across the Russian-speaking criminal-developer ecosystem.
On the OAK Software-vs-Group split. OAK-S34 (this entry) is the RansomHub encryptor codebase and brand; OAK-G15 (drafted in parallel) is the RansomHub operator cluster. The split mirrors the OAK-S23 / OAK-G05 LockBit pattern; the principal asymmetry is that the RansomHub operator cluster has neither named-defendant indictment nor OFAC institutional-cluster designation as of v0.1, with attribution architecture relying on the CISA AA24-242A four-agency joint advisory and CTI-vendor cluster-level tracking. The attribution-architecture-thinness is similar to Akira's (OAK-S33) and is diagnostic of the typical attribution surface for a 2024-emergent RaaS brand before sufficient enforcement-tempo accumulates.
On takedown / disruption history. RansomHub has not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action as of v0.1. The brand's continued operations through 2024 and into 2025 reflect the same structural challenge of disrupting Russian-jurisdiction-based operator cohorts that produced the LockBit / Akira / Black Basta operational-continuity patterns, combined with RansomHub's specific advantage of having captured the displaced-affiliate cohort from two prior major-brand disruptions, which made the brand's affiliate cohort more-experienced and more-distributed than any single-emergence RaaS brand. The U.S. government's enforcement-tempo response in 2025 was an open empirical question as of v0.1; the AA24-242A advisory architecture provided the institutional-attribution surface that would precede any future named-defendant or OFAC designation actions.