ATT&CKReferencesGroup-IB RansomHub FEB 2025

Group-IB RansomHub FEB 2025

Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareRansomHub

RansomHub can enumerate all accessible machines from the infected system.

T1021.002
SMB/Windows Admin Shares
MalwareRansomHub

RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2.

T1027.013
Encrypted/Encoded File
MalwareRansomHub

RansomHub has an encrypted configuration file.

T1059.001
PowerShell
MalwareRansomHub

RansomHub can use PowerShell to delete volume shadow copies.

T1059.003
Windows Command Shell
MalwareRansomHub

RansomHub can use `cmd.exe` to execute multiple commands on infected hosts.

T1070.004
File Deletion
MalwareRansomHub

RansomHub has the ability to self-delete.

T1082
System Information Discovery
MalwareRansomHub

RansomHub can retrieve information about virtual machines.

T1083
File and Directory Discovery
MalwareRansomHub

RansomHub has the ability to only encrypt specific files.

T1090
Proxy
MalwareRansomHub

RansomHub can use a proxy to connect to remote SFTP servers.

T1135
Network Share Discovery
MalwareRansomHub

RansomHub has the ability to target specific network shares for encryption.

T1140
Deobfuscate/Decode Files or Information
MalwareRansomHub

RansomHub can use a provided passphrase to decrypt its configuration file.

T1480
Execution Guardrails
MalwareRansomHub

RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration.

T1486
Data Encrypted for Impact
MalwareRansomHub

RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files.

T1489
Service Stop
MalwareRansomHub

RansomHub has the ability to terminate specified services.

T1490
Inhibit System Recovery
MalwareRansomHub

RansomHub has used `vssadmin.exe` to delete volume shadow copies.

T1497.003
Time Based Checks
MalwareRansomHub

RansomHub can sleep for a set number of minutes before beginning execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareRansomHub

RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument.

T1685.005
Clear Windows Event Logs
MalwareRansomHub

RansomHub can delete events from the Security, System, and Application logs.

T1688
Safe Mode Boot
MalwareRansomHub

RansomHub can reboot targeted systems into Safe Mode prior to encryption.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.