ATT&CKReferencesCISA RansomHub AUG 2024

CISA RansomHub AUG 2024

CISA et al. (2024, August 29). #StopRansomware: RansomHub Ransomware. Retrieved March 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareRansomHub

RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.

T1486
Data Encrypted for Impact
MalwareRansomHub

RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files.

T1490
Inhibit System Recovery
MalwareRansomHub

RansomHub has used `vssadmin.exe` to delete volume shadow copies.

T1491.001
Internal Defacement
MalwareRansomHub

RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.