Site icon TheCyberThrone

RansomHub Predessor is Believed to be Knight ransomware

Advertisements

The RansomHub ransomware is believed to be a rebranded version of Knight ransomware that came into evolution last year.

Knight ransomware target is multiple platforms, including Windows, Linux, macOS, ESXi, and Android. The operators used a double extortion model for their RaaS operation. The abrupt shutdown of the RaaS earlier this year and the malware’s source code was likely sold to the threat actor who relaunched the RansomHub operation.

Advertisements

Symantec researchers found multiple similarities between the RansomHub and Knight ransomware families, suggesting a common origin:

RansomHub only emerged in February 2024, it has rapidly grown and, over the past three months, has become the fourth most prolific ransomware operator based on the number of publicly claimed attacks.

Advertisements

The report states that one factor contributing to RansomHub growth is its success in attracting some large former affiliates of the Noberus ransomware group, which closed earlier this year. One former Noberus affiliate known as Notchy is now reportedly working with RansomHub. In addition to this, tools previously associated with another Noberus affiliate known as Scattered Spider were used in a recent RansomHub attack.

Reference- Security Affiars

Exit mobile version