ZeroFox Intelligence Flash Report - Second New RaaS of 2024 Announced in Dark Web Forum
|by Alpha Team

ZeroFox Intelligence Flash Report - Second New RaaS of 2024 Announced in Dark Web Forum
Product Serial: F-2024-02-07a
TLP:CLEAR
In this flash report, ZeroFox researchers report on the announcement of a new Ransomware-as-a-Service (RaaS) operation known as Ransomhub on the predominantly Russian-speaking dark web forum RAMP; it is the second RaaS launched on the forum in 2024.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On February 2, 2024, English-speaking threat actor “koley” announced the launch of a Ransomware-as-a-Service (RaaS) project named Ransomhub. The announcement, which was made in the Russian-speaking dark web forum “RAMP”, revealed that affiliates are now being sought.
- Ransomhub allegedly offers affiliates a host of new features, such as daily re-encryption and access to a control panel comprising a unique .onion domain address.
- The announcement about Ransomhub in English aligns with the recently-observed trend of English-speaking actors being willing to enter the traditionally Russian-dominated ransomware scene, as well as post in Russian-speaking dark web forums.
- The recent increase in new RaaS operations observed by ZeroFox is likely contributed to by the recent disruption of several prolific ransomware and digital extortion (R&DE) threat collectives.
Tags: tlp:clear, threat actor, DDW Ransomware