Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ RansomHub

🌐RansomHub

🌐 RansomHub is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 14 detection use cases to this actor across 51 MITRE ATT&CK techniques, with 3 threat-intel articles citing them. Active in our corpus from 2026-03-19 to 2026-06-11.

crit 3
View full actor card → All threat actors
14Use cases
3Articles
51Techniques
0IOCs

Known aliases

RansomHub

Top techniques

All other tracked techniques

Detection use cases (14)

RansomHub EDRKillShifter BYOVD — vulnerable driver loaded + EDR/AV process termination AI · profile SDD RansomHub Rclone exfiltration to MEGA / cloud storage prior to encryption AI · profile SΣDD Miasma worm GitHub commit-search C2 magic strings on command line or script Bespoke Miasma supply-chain worm leaked repo clone, install or fetch Bespoke Beaconing — periodic outbound to small set of destinations Internal Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Remote service execution — PsExec / SMB lateral movement Internal Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal OAuth consent / suspicious app grant Internal

Threat-intel articles (3)