🌐RansomHub
🌐 RansomHub is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 14 detection use cases to this actor across 51 MITRE ATT&CK techniques, with 3 threat-intel articles citing them. Active in our corpus from 2026-03-19 to 2026-06-11.
crit 3
14Use cases
3Articles
51Techniques
0IOCs
Known aliases
RansomHub
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1014 · RootkitT1021.001 · Remote Desktop ProtocolT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.009 · Embedded PayloadsT1037.001 · Logon Script (Windows)T1055 · Process InjectionT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1071.001 · Web ProtocolsT1071.004 · DNST1098.001 · Additional Cloud CredentialsT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1190 · Exploit Public-Facing ApplicationT1195.001 · Compromise Software Dependencies and Development ToolsT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1489 · Service StopT1490 · Inhibit System RecoveryT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1555.003 · Credentials from Web BrowsersT1562.001 · T1562.001T1562.004 · T1562.004T1562.006 · T1562.006T1562.009 · T1562.009T1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.004 · Spearphishing VoiceT1569.002 · Service ExecutionT1574.002 · T1574.002T1588.001 · Malware
Detection use cases (14)
RansomHub EDRKillShifter BYOVD — vulnerable driver loaded + EDR/AV process termination RansomHub Rclone exfiltration to MEGA / cloud storage prior to encryption Miasma worm GitHub commit-search C2 magic strings on command line or script Miasma supply-chain worm leaked repo clone, install or fetch Beaconing — periodic outbound to small set of destinations Suspicious browser extension installation Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Remote service execution — PsExec / SMB lateral movement Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard OAuth consent / suspicious app grantThreat-intel articles (3)
crit What the ransom note won’t say · 2026-04-20
crit EDR killers explained: Beyond the drivers · 2026-03-19