Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ RansomHub

🌐RansomHub

🌐 RansomHub is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 14 detection use cases to this actor across 42 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2026-03-19 to 2026-07-25.

crit 4
View full actor card → All threat actors
14Use cases
4Articles
42Techniques
0IOCs

Known aliases

RansomHub

Top techniques

All other tracked techniques

Detection use cases (14)

RansomHub EDRKillShifter — BYOVD vulnerable-driver service install from user-writable path AI · profile SΣDD RansomHub recovery inhibition + service stop chain preceding encryption AI · profile SΣDD DevMan/Funky Mantis locker execution by known SHA256/MD5 hash Bespoke DevMan ransomware encryption artifacts: .devman extension and deterministic ransom note Bespoke DevMan pre-encryption recovery inhibition and event-log clearing Bespoke Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Remote service execution — PsExec / SMB lateral movement Internal OAuth consent / suspicious app grant Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal

Threat-intel articles (4)