CISA et al. (2024, August 29). #StopRansomware: RansomHub Ransomware. Retrieved March 17, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareRansomHub | RansomHub can stop processes associated with files currently in use to maximize the impact of encryption. |
| T1486 Data Encrypted for Impact |
MalwareRansomHub | RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files. |
| T1490 Inhibit System Recovery |
MalwareRansomHub | RansomHub has used `vssadmin.exe` to delete volume shadow copies. |
| T1491.001 Internal Defacement |
MalwareRansomHub | RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.