RansomHub: New Ransomware with Origins in Older Knight

June 6, 2024, 8:09 a.m.

Description

A rapidly emerging operation called RansomHub has rapidly grown into one of the largest ransomware threats currently active. Analysis reveals RansomHub is likely an updated and rebranded version of the older Knight ransomware, suggesting the developers bought Knight's source code after its developers ceased operations and revamped it. Despite shared origins, the current operators are unlikely the original Knight creators, but rather experienced actors in the cybercriminal underground who successfully attracted former affiliates of defunct groups like Noberus. Key similarities include code overlap, nearly identical help menus, string obfuscation techniques, and ransom note structure, indicating Knight formed the foundation for RansomHub.

Date

Published Created Modified
June 6, 2024, 7:46 a.m. June 6, 2024, 7:46 a.m. June 6, 2024, 8:09 a.m.

Indicators

fb9f9734d7966d6bc15cce5150abb63aadd4223924800f0b90dc07a311fb0a7e

f1a6e08a5fd013f96facc4bb0d8dfb6940683f5bdfc161bd3a1de8189dea26d3

ea9f0bd64a3ef44fe80ce1a25c387b562a6b87c4d202f24953c3d9204386cf00

e654ef69635ab6a2c569b3f8059b06aee4bce937afb275ad4ec77c0e4a712f23

a96a0ba7998a6956c8073b6eff9306398cc03fb9866e4cabf0810a69bb2a43b2

8f59b4f0f53031c555ef7b2738d3a94ed73568504e6c07aa1f3fa3f1fd786de7

7539bd88d9bb42d280673b573fc0f5783f32db559c564b95ae33d720d9034f5a

7114288232e469ff368418005049cf9653fe5c1cdcfcd63d668c558b0a3470f2

595cd80f8c84bc443eff619add01b86b8839097621cdd148f30e7e2214f2c8cb

36e5be9ed3ec960b40b5a9b07ba8e15d4d24ca6cd51607df21ac08cda55a5a8e

34e479181419efd0c00266bef0210f267beaa92116e18f33854ca420f65e2087

2f3d82f7f8bd9ff2f145f9927be1ab16f8d7d61400083930e36b6b9ac5bbe2ad

104b22a45e4166a5473c9db924394e1fe681ef374970ed112edd089c4c8b83f2

02e9f0fbb7f3acea4fcf155dc7813e15c1c8d1c77c3ae31252720a9fa7454292

Attack Patterns

RansomHub

Snatch

Cyclops Blink - S0687

Knight

RansomHub

T1578

T1556

T1490

T1583

T1018

T1136

T1567

T1114

T1021

T1489

T1486

T1070

T1082

T1105

T1592

T1027

T1053

T1190

T1072

T1059

CVE-2020-1472