RANSOMHUB
DRAGONFORCE
ALPHV
RansomwareMalwareNewsAugust 27, 202515 min read

The Rise and Sudden Silence of RansomHub

From ALPHV's exit scam to the most prolific RaaS operation of 2024 — and then a hostile takeover by DragonForce. A complete threat analysis and defense strategy.

Scroll

The ransomware ecosystem is characterized by rapid shifts in power. Following the significant disruption of LockBit and the dramatic exit scam of ALPHV/BlackCat in early 2024, RansomHub rapidly emerged to become the most prolific Ransomware-as-a-Service (RaaS) operation by late 2024 and early 2025.

The Rapid Ascent and Abrupt Fall

RansomHub announced its operations in February 2024 on the RAMP cybercriminal forum. Its timing was impeccable, capitalizing on the distrust sown by the ALPHV/BlackCat exit scam.

The Change Healthcare Catalyst

ALPHV/BlackCat infamously attacked Change Healthcare, leading to a reported $22 million ransom payment. The ALPHV operators allegedly stole the funds, failing to pay the affiliate "Notchy" who executed the attack. RansomHub seized this opportunity, offering a lucrative 90/10 revenue split favoring affiliates and allowing them to receive payments directly.

The Knight Ransomware Lineage

Security researchers widely agree that RansomHub is a rebranded version of Knight ransomware (formerly Cyclops). Significant code overlap confirms this lineage: written primarily in Go (Golang) with C++ for ESXi targeting, use of Gobfuscate for obfuscation, and the capability to restart endpoints in Safe Mode before encryption.

The 2025 Shutdown

On March 31, 2025, RansomHub's leak site and negotiation portals went offline. DragonForce announced that RansomHub had "joined the cartel." Subsequent forum posts accused DragonForce of a hostile takeover. As of August 2025, RansomHub is considered inactive.

Tactics, Techniques, and Procedures

1. Initial Access

2. Execution and Persistence

3. Defense Evasion

4. Discovery and Lateral Movement

5. Exfiltration and Impact

Threat Hunting Guidance

Hunting for BYOVD and EDR Killers

Anomalous RMM Tool Usage

Recovery Inhibition Detection

How Mjolnir Security Can Help

The ransomware landscape evolves rapidly. Organizations need a proactive and adaptive defense strategy.

Threat-Informed DefenseRansomware Readiness AssessmentAdversary EmulationPurple Teaming24/7 MDRVulnerability ManagementEmergency IRDigital Forensics
  • Proactive Defense: Threat-informed defense strategy, ransomware readiness assessments, and adversary emulation simulating RansomHub TTPs.
  • Detection and Response: 24/7 SOC actively hunting for pre-ransom behavioral indicators, specializing in detecting abuse of legitimate tools.
  • Incident Response and Recovery: Emergency IR with rapid deployment for containment, eradication, and secure restoration of operations.
Written by: Mjolnir Security  |  Published: August 27, 2025