RansomHub: New Ransomware with Origins in Older Knight

June 6, 2024, 8:09 a.m.

Description

A rapidly emerging operation called RansomHub has rapidly grown into one of the largest ransomware threats currently active. Analysis reveals RansomHub is likely an updated and rebranded version of the older Knight ransomware, suggesting the developers bought Knight's source code after its developers ceased operations and revamped it. Despite shared origins, the current operators are unlikely the original Knight creators, but rather experienced actors in the cybercriminal underground who successfully attracted former affiliates of defunct groups like Noberus. Key similarities include code overlap, nearly identical help menus, string obfuscation techniques, and ransom note structure, indicating Knight formed the foundation for RansomHub.

Date

  • Created: June 6, 2024, 7:46 a.m.
  • Published: June 6, 2024, 7:46 a.m.
  • Modified: June 6, 2024, 8:09 a.m.

Indicators

  • fb9f9734d7966d6bc15cce5150abb63aadd4223924800f0b90dc07a311fb0a7e
  • f1a6e08a5fd013f96facc4bb0d8dfb6940683f5bdfc161bd3a1de8189dea26d3
  • ea9f0bd64a3ef44fe80ce1a25c387b562a6b87c4d202f24953c3d9204386cf00
  • e654ef69635ab6a2c569b3f8059b06aee4bce937afb275ad4ec77c0e4a712f23
  • a96a0ba7998a6956c8073b6eff9306398cc03fb9866e4cabf0810a69bb2a43b2
  • 8f59b4f0f53031c555ef7b2738d3a94ed73568504e6c07aa1f3fa3f1fd786de7
  • 7539bd88d9bb42d280673b573fc0f5783f32db559c564b95ae33d720d9034f5a
  • 7114288232e469ff368418005049cf9653fe5c1cdcfcd63d668c558b0a3470f2
  • 595cd80f8c84bc443eff619add01b86b8839097621cdd148f30e7e2214f2c8cb
  • 36e5be9ed3ec960b40b5a9b07ba8e15d4d24ca6cd51607df21ac08cda55a5a8e
  • 34e479181419efd0c00266bef0210f267beaa92116e18f33854ca420f65e2087
  • 2f3d82f7f8bd9ff2f145f9927be1ab16f8d7d61400083930e36b6b9ac5bbe2ad
  • 104b22a45e4166a5473c9db924394e1fe681ef374970ed112edd089c4c8b83f2
  • 02e9f0fbb7f3acea4fcf155dc7813e15c1c8d1c77c3ae31252720a9fa7454292

Attack Patterns

  • RansomHub
  • Snatch
  • Cyclops Blink - S0687
  • Knight
  • RansomHub
  • T1578
  • T1556
  • T1490
  • T1583
  • T1018
  • T1136
  • T1567
  • T1114
  • T1021
  • T1489
  • T1486
  • T1070
  • T1082
  • T1105
  • T1592
  • T1027
  • T1053
  • T1190
  • T1072
  • T1059

Linked vulnerabilities