zerofox logo
Advisories

ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory

Product Serial: F-2024-08-21a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on the digital extortion collective RansomHub, the regions and industries that they target, and the upward trajectory observed in their attack frequency.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • The ransomware-as-a-service (RaaS) operation “RansomHub” has almost certainly significantly increased its operational tempo in recent weeks, having conducted more attacks so far in Q3 2024 than in Q1 and Q2 2024 combined.
  • RansomHub’s activity as a proportion of all ransomware activity observed by ZeroFox is also on a sharp upward trajectory, with the group accounting for approximately 2 percent of all attacks in Q1, 5.1 percent in Q2, and 14.2 percent so far in Q3.
  • There is a likely chance that RansomHub will remain the most prominent ransomware collective for the coming months and continue to attract affiliates.
  • The collective will almost certainly continue to target a highly diverse array of sectors, and the proportion of attacks targeting organizations located in North America will very likely increase.

Tags: tlp:clear,  dark web,  threat actor