ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory
|by Alpha Team

ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory
Product Serial: F-2024-08-21a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the digital extortion collective RansomHub, the regions and industries that they target, and the upward trajectory observed in their attack frequency.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- The ransomware-as-a-service (RaaS) operation “RansomHub” has almost certainly significantly increased its operational tempo in recent weeks, having conducted more attacks so far in Q3 2024 than in Q1 and Q2 2024 combined.
- RansomHub’s activity as a proportion of all ransomware activity observed by ZeroFox is also on a sharp upward trajectory, with the group accounting for approximately 2 percent of all attacks in Q1, 5.1 percent in Q2, and 14.2 percent so far in Q3.
- There is a likely chance that RansomHub will remain the most prominent ransomware collective for the coming months and continue to attract affiliates.
- The collective will almost certainly continue to target a highly diverse array of sectors, and the proportion of attacks targeting organizations located in North America will very likely increase.
Tags: tlp:clear, dark web, threat actor