OAK — OnChain Attack Knowledge

Software · OAK-S34 · ransomware

OAK-S34 — RansomHub ransomware

Type
ransomware
Aliases
RansomHub (the operator-side and leak-site-branded name from the brand's February 2024 debut on Russian-language criminal forums); industry-side cross-attribution labels include the informal "Knight-derivative" naming used in mid-2024 industry reporting that documented partial code-reuse signals between the RansomHub Windows codebase and the prior Knight / Cyclops-Blink-class encryptor codebase (the operator-cohort behind Knight is widely read as having sold or licensed source code to the RansomHub developer team), and the "post-ALPHV-affiliate-absorber" descriptive used across CTI-vendor reporting to characterise the brand's principal market-positioning function in 2024. RansomHub is the canonical worked example of operator-cohort opportunism in the wake of a competitor brand's exit-scam-driven dissolution — the brand's rapid Q2–Q4 2024 growth is widely attributed to its capacity to absorb the high-tier ALPHV affiliate diaspora following the March 2024 ALPHV exit-scam (see OAK-S24 Discussion), with the "Notchy" affiliate behind the Change Healthcare attack widely-reported as having rotated onto the RansomHub affiliate panel.
Active
active — RansomHub-branded operations continued through 2024 and into 2025 with sustained leak-site cadence; brand-attributable extortion volume placed RansomHub as the top-by-leak-site-postings RaaS brand in H2 2024 per Recorded Future / Coveware tracking, displacing both the post-Cronos LockBit and the post-exit-scam ALPHV from their prior market-share positions. The brand had not been subjected to a government takedown comparable to Operation Cronos or the December 2023 ALPHV action as of v0.1, and remains an active-detection target.
First observed
2024-02 (RansomHub leak-site debut February 2024; advertisements on Russian-language criminal forums marked the brand's debut and the affiliate-onboarding panel was operational immediately, suggesting a substantial pre-launch development period and an operator-side cohort with prior RaaS-operational experience).
Used by Groups
OAK-G15 RansomHub (primary operator cluster — drafted in parallel with this Software entry; the operator cohort is tracked at cluster level rather than as a named-individual operator, with no senior-leadership indictment or OFAC designation as of v0.1). Affiliate-side cross-use spans the broader post-ALPHV affiliate diaspora; CISA / FBI / MS-ISAC / HHS joint advisory AA24-242A ([cisaaa24242a], August 29, 2024) provides the canonical confirmed-grade institutional-attribution document and explicitly identifies RansomHub as having absorbed affiliates from ALPHV and LockBit following the disruption events that affected those brands earlier in 2024.
Host platforms
Windows (primary, all enterprise-server variants, with the encryptor codebase showing partial structural similarities to the prior Knight / Cyclops-class codebase per Mandiant and Microsoft attribution work); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged in mid-2024); Go-language and Rust-language partial implementations have been documented in different RansomHub builds across 2024, with the dual-language architecture mirroring the broader sector pattern of hybrid-codebase RaaS designs established by Akira (OAK-S33) and the LockBit NG-Dev rewrite.
Observed Techniques
OAK-T7.001 (mixer-routed-hop, used for RansomHub-affiliate ransom proceeds with smaller-mixer-infrastructure routing observed post-Sinbad-takedown per Chainalysis tracking); OAK-T7.002 (CEX deposit-address layering, the dominant 2024 default with Garantex (OAK-G03) named in industry-forensic reporting as a recurring RansomHub-affiliate off-ramp consistent with the broader Russian-speaking-RaaS-cohort laundering pattern); OAK-T7.003 (cross-chain-bridge laundering, used in tail-affiliate flows tracked by Chainalysis as affiliates rotated away from compromised mixer infrastructure); OAK-T8.001 (common-funder cluster reuse, the load-bearing Technique for tracking the post-ALPHV affiliate-migration-into-RansomHub pattern — wallet-cluster persistence is the principal forensic signature that allowed Chainalysis, TRM Labs, and Mandiant to identify the absorption of named ALPHV affiliates into the RansomHub affiliate cohort).

Description

RansomHub is the ransomware encryptor codebase and brand maintained by a Russian-speaking operator cohort from February 2024 onward, emerging in the post-Cronos / post-ALPHV-exit-scam landscape with a market-positioning explicitly designed to capture the high-tier affiliate diaspora from the disrupted competitor brands. The brand's Q2–Q4 2024 growth — from a February 2024 cold start to the top-by-leak-site-postings RaaS brand by H2 2024 — is the cleanest documented case in the modern RaaS sector of rapid market-share capture via affiliate-cohort absorption from disrupted predecessor brands, and is the principal reason RansomHub's emergence is widely treated as a structural rather than incremental event in the post-Cronos ransomware-sector trajectory.

The encryptor's distinguishing technical features include the Knight / Cyclops-class codebase derivation (partial source-code lineage to a 2023-era Russian-speaking-cohort encryptor, providing the developer-side technical substrate for the brand's rapid operational-launch capacity), a dual-language architecture across Windows and Linux/ESXi variants (Go and Rust components documented in different builds across 2024), aggressive partial-encryption mode for speed-versus-stealth tradeoff, and an affiliate-program structure with a 90/10 affiliate/operator split (publicly advertised on Russian-language criminal forums as the most affiliate-favourable split in the sector at the time of launch) — the low operator-cut was a deliberate market-positioning choice to attract the high-tier affiliate cohort displaced from ALPHV (which had run a 80/20-to-90/10 split itself before the exit-scam) and from LockBit (which had run a 80/20 split before Operation Cronos).

The CISA / FBI / MS-ISAC / HHS joint advisory AA24-242A of August 29, 2024 ([cisaaa24242a]) is the canonical confirmed-grade institutional-attribution document for the brand, documenting over 210 victim organisations through August 2024 and explicitly identifying RansomHub as having absorbed affiliates from ALPHV and LockBit following the disruption events that affected those brands earlier in 2024. The advisory's targeting of healthcare and public-health verticals as the priority concern reflects the post-Change-Healthcare regulatory-and-political-attention surface in U.S. healthcare cybersecurity, and the four-agency joint format (CISA / FBI / MS-ISAC / HHS) signals the same sector-priority architecture used for AA24-131A (Black Basta) following the May 2024 Ascension Health incident.

The family's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader post-Conti / post-ALPHV affiliate-cohort laundering pattern. The on-chain-side defining signature for RansomHub's 2024 trajectory is the wallet-cluster persistence (OAK-T8.001) connecting RansomHub-attributable affiliate clusters to prior ALPHV-attributable affiliate clusters — the same affiliate operators rotated wallet-funding patterns onto RansomHub-issued payment addresses while retaining the upstream-funding-source topology that anchored their ALPHV-era activity, producing one of the cleanest documented cases of cross-brand-affiliate-continuity-via-on-chain-wallet-cluster-tracking in the modern RaaS forensic record.

Observed examples

  • Change Healthcare (post-March 2024 secondary leak). Following the ALPHV operators' exit-scam diversion of the ~$22M Change Healthcare ransom payment in early March 2024, the "Notchy" affiliate (the operator behind the Change Healthcare deployment under the ALPHV brand) re-published the stolen Change Healthcare data on the RansomHub leak site in April 2024, demanding a second ransom from UnitedHealth Group. The episode is the canonical worked example of post-exit-scam-affiliate-rotation as continuity tooling and the cleanest single-affiliate evidentiary chain for the ALPHV-to-RansomHub absorption pattern. Confirmed-grade per industry reporting and [cisaaa24242a] cohort context.
  • Christie's auction house incident (May 2024). RansomHub-claimed deployment against Christie's during the spring 2024 auction season; data published on the RansomHub leak site after non-payment; one of the higher-profile financial-services-adjacent incidents of 2024. Confirmed-grade per Christie's own incident-disclosure and RansomHub leak-site posting.
  • Frontier Communications incident (April 2024). RansomHub-claimed deployment against Frontier Communications, a major U.S. telecommunications provider; data published on the RansomHub leak site; one of the more-prominent 2024 telecommunications-sector incidents. Confirmed-grade per Frontier 8-K disclosure and RansomHub leak-site posting.
  • Rite Aid incident (June 2024). RansomHub-claimed deployment against Rite Aid pharmacy chain; data published on the RansomHub leak site after non-payment; representative of the 2024 retail-pharmacy-sector incident pattern. Confirmed-grade per Rite Aid incident-disclosure.
  • CISA AA24-242A campaign cohort (February–August 2024). The advisory documents over 210 named-and-unnamed RansomHub victim organisations across U.S. critical-infrastructure sectors with healthcare, water-and-wastewater, IT, government, and emergency-services verticals prominently called out. Confirmed-grade aggregate per [cisaaa24242a].
  • OAK on-chain example surface. The Change Healthcare secondary-leak episode of April 2024 is the strongest candidate for a future OAK example entry showing the OAK-S34-binary × cross-brand affiliate-rotation × T8.001 worked example, paired with the existing Change-Healthcare-on-chain-trace evidence base from OAK-S24 BlackCat / ALPHV. The structural framing would document the affiliate-side wallet-cluster continuity across the ALPHV-to-RansomHub brand-rotation as the on-chain attribution signature.

Detection / attribution signals

Defenders should treat RansomHub detection as a host-layer + on-chain-layer joint problem with the cross-brand-affiliate-continuity tracking at the OAK-T8.001 level as the principal forensic signature distinguishing post-ALPHV-rotation affiliates from independent emergence:

  • Host-layer process-tree fingerprints — characteristic file-extension changes (random-string extensions appended to encrypted files, with per-affiliate-configurable patterns); ransom-note filenames (README.txt per-folder); Windows-binary signature with partial structural similarities to the prior Knight / Cyclops codebase documented by Mandiant and Microsoft; Go-language and Rust-language signatures in different builds across 2024; partial-encryption mode signature; ESXi-variant invokes the standard esxcli VM-shutdown sequence shared across post-2022 RaaS brands.
  • Pre-encryption tradecraft — initial access via VPN-credential brute-force (against Cisco, Fortinet, Palo Alto, Citrix appliances), ZeroLogon (CVE-2020-1472) where unpatched, ConnectWise ScreenConnect vulnerabilities (CVE-2024-1709, CVE-2024-1708), and other commodity-RCE entry points; post-foothold deployment of Cobalt Strike (OAK-S37) and Sliver / Brute Ratel C2; credential theft via Mimikatz and the standard Russian-speaking-RaaS-cohort tooling; lateral movement via PsExec, WMI, and operator-bundled deployment scripts.
  • Network-layer telemetry — Cobalt Strike post-exploitation deployment after VPN-credential or RCE foothold; data-exfiltration to operator-controlled cloud-storage staging (Mega.io, rclone-to-S3); leak-site negotiation-portal access patterns; RansomHub leak-site infrastructure operated continuously through 2024 with operator-side rotation onto multiple bulletproof-hosting providers documented.
  • On-chain-layer signatures (the OAK-relevant signal — the load-bearing detection vector for RansomHub specifically) — RansomHub affiliate-controlled ransom-payment wallets exhibit common-funder cluster reuse (OAK-T8.001) with prior ALPHV-attributable affiliate clusters at a density unmatched by any independent-emergence RaaS brand, providing the principal forensic anchor for the post-ALPHV affiliate-absorption attribution work; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; the per-incident ransom volumes span the full small-to-large enterprise spectrum (the 90/10 affiliate split attracted both small-incident-high-cadence affiliates and large-incident-low-cadence affiliates), producing a heterogeneous on-chain signature relative to the more-uniform Akira pattern.
  • CTI vendor coverage — Mandiant (RansomHub intrusion-set tracking and the Knight-derivative codebase attribution work), Microsoft Threat Intelligence (RansomHub / Storm-class tracking and the post-ALPHV affiliate-migration documentation), Sophos (sustained "State of Ransomware" reporting and the RansomHub-rapid-emergence analysis), Trend Micro (continuous version-by-version analysis), Recorded Future (Insikt Group sustained RansomHub-and-affiliate-migration reporting), Coveware (incident-response-side payment and negotiation-pattern reporting), Chainalysis and TRM Labs (on-chain affiliate-cluster cross-brand-continuity tracking — the load-bearing CTI surface for RansomHub specifically).

Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA24-242A and live CTI-vendor feeds named above.

Citations

  • [cisaaa24242a] — CISA / FBI / MS-ISAC / HHS joint advisory AA24-242A on RansomHub ransomware, August 29, 2024. (NEW citation — see summary.)
  • [mandiantransomhub2024] — Mandiant RansomHub intrusion-set tracking and Knight-derivative codebase attribution. (NEW citation — see summary.)
  • [microsoftransomhub2024] — Microsoft Threat Intelligence RansomHub / post-ALPHV-affiliate-migration analysis. (NEW citation — see summary.)
  • [sophosransomhub2024] — Sophos RansomHub rapid-emergence and tradecraft analysis. (NEW citation — see summary.)
  • [trendmicroransomhub2024] — Trend Micro RansomHub version-by-version analysis. (NEW citation — see summary.)
  • [chainalysisransomhub2024] — Chainalysis RansomHub-attributable ransom-payment-volume tracking and post-ALPHV-affiliate-migration wallet-cluster analysis. (NEW citation — see summary.)
  • [recordedfutureransomhub2024] — Recorded Future / Insikt Group sustained RansomHub-and-affiliate-migration reporting. (NEW citation — see summary.)
  • [ofac2022garantex] — Treasury OFAC Garantex designation press release; broader Russian-speaking-RaaS-cohort laundering-venue context.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; cross-family context for the RansomHub volume distribution and post-ALPHV market-share-capture.

Discussion

On the post-ALPHV-affiliate-absorption pattern as the central framing. OAK-S34's principal value as a Software entry is as the canonical worked example of rapid market-share capture via affiliate-cohort absorption from disrupted predecessor brands. The brand's February 2024 cold-start-to-H2-2024-top-by-leak-site-postings trajectory is the cleanest documented case of this pattern in the modern RaaS sector and is structurally distinct from the codebase-version-rotation continuity (LockBit), the codebase-derivative successor-brand continuity (Black Basta, Royal/BlackSuit), and the independent-operator emergence pattern (Akira). The 90/10 affiliate/operator split is the load-bearing market-positioning lever that enabled the absorption, and it provides a useful comparative reference for understanding the operator-side economic-incentive engineering that shapes affiliate-cohort migration patterns in the modern RaaS sector.

On the Change Healthcare secondary-leak episode as evidentiary anchor. The April 2024 Change Healthcare data re-publication on the RansomHub leak site by the "Notchy" affiliate is the cleanest single-affiliate evidentiary chain for the ALPHV-to-RansomHub absorption pattern — a single named affiliate, with documented prior-ALPHV-affiliation, executing a documented post-exit-scam rotation onto the RansomHub affiliate panel within weeks of the ALPHV dissolution, with the rotation visible in both the leak-site evidence and the on-chain wallet-cluster persistence at the OAK-T8.001 level. The episode anchors a substantial fraction of the post-ALPHV-affiliate-migration attribution work and is the principal evidentiary basis for the CISA AA24-242A advisory's explicit identification of RansomHub as an ALPHV-affiliate-absorber.

On predecessors at the codebase level. RansomHub's encryptor codebase shows partial structural similarities to the prior Knight / Cyclops-class encryptor (a 2023-era Russian-speaking-cohort encryptor that had been advertised for sale on Russian-language criminal forums), suggesting a purchased-or-licensed-source-code basis for the developer-side technical substrate. This pattern — a new operator cohort acquiring source code from a prior cohort to bootstrap the technical substrate of a new brand — is structurally distinct from the leaked-source-code-fork pattern (LockBit Green / Conti v3) and from the in-house-development pattern (ALPHV's clean Rust rewrite) and is one of several mechanisms through which RaaS encryptor codebases circulate across the Russian-speaking criminal-developer ecosystem.

On the OAK Software-vs-Group split. OAK-S34 (this entry) is the RansomHub encryptor codebase and brand; OAK-G15 (drafted in parallel) is the RansomHub operator cluster. The split mirrors the OAK-S23 / OAK-G05 LockBit pattern; the principal asymmetry is that the RansomHub operator cluster has neither named-defendant indictment nor OFAC institutional-cluster designation as of v0.1, with attribution architecture relying on the CISA AA24-242A four-agency joint advisory and CTI-vendor cluster-level tracking. The attribution-architecture-thinness is similar to Akira's (OAK-S33) and is diagnostic of the typical attribution surface for a 2024-emergent RaaS brand before sufficient enforcement-tempo accumulates.

On takedown / disruption history. RansomHub has not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action as of v0.1. The brand's continued operations through 2024 and into 2025 reflect the same structural challenge of disrupting Russian-jurisdiction-based operator cohorts that produced the LockBit / Akira / Black Basta operational-continuity patterns, combined with RansomHub's specific advantage of having captured the displaced-affiliate cohort from two prior major-brand disruptions, which made the brand's affiliate cohort more-experienced and more-distributed than any single-emergence RaaS brand. The U.S. government's enforcement-tempo response in 2025 was an open empirical question as of v0.1; the AA24-242A advisory architecture provided the institutional-attribution surface that would precede any future named-defendant or OFAC designation actions.

Techniques observed (4)

Used by