ZeroFox Intelligence Flash Report - Speculation Unfolds Surrounding RansomHub Cessation
|by Alpha Team

ZeroFox Intelligence Flash Report - Speculation Unfolds Surrounding RansomHub Cessation
Product Serial: F-2025-04-09a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on a recent reduction in attacks from the ransomware and digital extortion collective RansomHub, as well as speculation within dark web forums surrounding the collective's victim leak site.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Ransomware and digital extortion (R&DE) collective RansomHub’s dark web victim leak site has been offline since April 1, 2025, and no new victims have been observed.
- Around April 4, an account associated with the DragonForce R&DE collective posted on the Russian-speaking deep and dark web (DDW) forum RAMP, claiming that RansomHub “will be up soon” and that RansomHub had decided to move to DragonForce’s infrastructure.
- As of the writing of this report, RansomHub is very likely non-operational, posing a significantly reduced threat to global organizations across industries. There is a likely chance that RansomHub will remain non-operational during the coming weeks.
- Should RansomHub’s operations recommence, the collective will very likely suffer from significant reputational damage, regardless of whether original RansomHub or DragonForce infrastructure is leveraged.
Tags: tlp:clear, dark web, MAL Ransomware