ZeroFox Intelligence Profile - RansomHub Ransomware
|by Alpha Team

ZeroFox Intelligence Profile - RansomHub Ransomware
Product Serial: B-2025-02-28a
TLP:GREEN
RansomHub (former aliases: Cyclops and Knight) is a ransomware-as-a-service (RaaS) variant initially launched on the predominantly Russian-speaking dark web forum RAMP in February 2024. Since their launch, ZeroFox observed RansomHub’s activity had accounted for an estimated 2 percent of all attacks in the first quarter of 2024, 5 percent in the second quarter, and 14 percent in the third quarter with approximately 34 percent of RansomHub’s attacks targeted European-based organizations in comparison to 25 percent across the general threat landscape. RansomHub employs common ransomware TTPs such as phishing, vulnerability exploitation and utilizes a double extortion model for monetary gain.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Tags: threat actor, tlp:green