Go back

RansomHub: From RaaS Kingpin to Cartel Mystery

40m 5s

RansomHub: From RaaS Kingpin to Cartel Mystery

The transcription discusses the sudden disappearance of the ransomware group Ransom Hub, known for its extensive operations and unique features like SFTP data encryption. The origin of Ransom Hub is speculated to be linked to Black Cat, with commonalities in their operations. The group targeted critical infrastructure, especially healthcare organizations, to increase ransom payment likelihood. Affiliates played a crucial role in carrying out attacks on behalf of Ransom Hub. The impact of Ransom Hub on businesses globally was significant, and its sudden disappearance has led to uncertainty in the ransomware marketplace. Recommendations for businesses to avoid ransomware attacks include patching vulnerable devices, avoiding weak passwords, implementing two-factor authentication, and segregating servers and workstations. The landscape of ransomware groups has become more fragmented, with affiliates switching between groups based on recommendations, features, and propaganda. The concerns for businesses remain high, as the affiliates conducting attacks may continue operations with similar tactics and tools even after Ransom Hub's disappearance.

Transcription

5008 Words, 29241 Characters

Imagine you're at work tapping away at an email when suddenly you get a message that changes everything. It's a note that tells you your company's servers have been breached and your data stolen and encrypted. The note goes on to deliver the good news that your data is for now secure and that nobody knows about the breach. It warns against reaching out to the authorities for help and says that any action will have irreversible negative consequences for your business, including the publication of the stolen data and details of the hack. The solution you read is really quite simple. You have to pay up, pay the ransom and the problem goes away in 24 hours guaranteed. Before April of this year, that ransom note might be signed by one of the most prolific gangs of online extortionists around the globe, a group responsible for over 600 attacks and multi-million dollars of stolen money. But then they vanished, their web pages went dark, their thriving ransomware operation vanished overnight and their members scattered to rival groups across the dark web. Now there are two questions on everyone's lips. What does that mean for the ransomware marketplace and what exactly happened to the cyber criminal group codenamed Ransom Hub? Alright, let's dive right into this episode. So we have an exciting guest joining us this week, Cyber Threat Intelligence Analyst and Group I.B.'s Ransom Hub Expert Pietro. Pietro, now you've been close to the ground on this one. I know it. You're our ransomware expert. So you're working as part of the Cyber Threat Intelligence Team investigating Ransom Hubs operations and delivering crucial updates and information to help fight back against this prominent ransomware as a service group. We're pleased that you've joined us to share your insights. Let's first get into some of the basics. Can you tell us a little bit about the origins of Ransom Hub? When did Group I.B. or you become aware of them? Thanks Nick. Thanks Gary for having me here. I really have to be here. The first time we heard about the Ransom Hub was in February of the last year, when they first published the partnership program on Ramp Forum. But one of the accounts used by Ransom Hub admin called Coley was created in this forum, I mean a Ramp Forum on May 2023. The group Ransom Hub may have started even before the first victim was published in the idea of us. The origin of Ransom Hub is quite confusing. A lot of people think that Ransom Hub is a rebrand of Black Cat and there are some reasons for that. The first one is because the partnership program of Ransom Hub was published right after Black Cat exited SCAM. The second reason is because one of the victims, a big company that was published in the Ransom Hub DLS was previously published in the Black Cat DLS. In addition to that, we also have some common features in the Ransom Hub, like a feature that modifies synlinks in the Ransom Hub that is also available in the Black Cat Ransom Hub. And also some instructions that we found in the Affiliate Panel of Ransom Hub are present in the Black Cat Affiliate Panel. Ransom Hub may have been created by Nochi, which was a former Black Cat Affiliate. But of course, it's too confusing, but I think that's the best theory. I do not think that Ransom Hub was a rebrand of Black Cat, but a group created by former Black Cat Affiliate and night Ransom Hub developers. And Ransom Hub is a service provider, right? If I was to try and join this thing, what would that look like? What sort of things would they give me to then enable me to go and carry out attacks? Yeah, that's important to distinguish affiliates from Ransom as a service groups. Ransom as a service groups, those who provide resources to criminals to encrypt data, to extort companies and to negotiate with the companies. But because there are a lot of Ransom groups, Ransom as a service operations, they may eventually provide additional resources like killers, which is a kind of tool that they use to bypass detection and some security solutions. Some of them may provide the DOS or you can even call a victim right from the affiliate panel. The resources that Ransom Hub provided through their affiliates was the Ransomware, the DLS, the Affiliate Panel, where they could configure and build the Ransomware and also some killers that were able to bypass some security solutions and also some post-exploitation tools. The Ransomware developed by Ransom Hub is very similar to most of the Ransomware we see nowadays. I mean, you see features like killing processes, stopping services. They're able to use techniques like the hash, pass the ticket and stuff like that. But there was one special feature in the Ransom Hub, which was the feature that allowed criminals to encrypt data via SFTP protocol. So that was a feature that I've never, ever seen before. There are some other groups like killing that also provide some features in the Ransomware, which allow remote data encryption, but they do not use SFTP. So that was the first time I see that. And it's reported that Ransom Hub is the biggest Ransomware as a service operator, bigger than LockBit. How did they pull that off in such a short time? In 2024, because of the amount of the companies that were disclosed in the Ransom Hub TLS, we can say that it was much bigger than the amount of companies published on LockBit TLS. But I do not think that Ransom Hub was a special and great Ransomware as a service operation. The thing is that when they emerged, LockBit was impacted by a law enforcement operation called Operation Chronos. So that's one of the reasons why they became such a big Ransomware as a service operation with a lot of affiliates. But there are some additional reasons I would like to mention here. One of them is because the Black Hat and LockBit Ransomware operations were impacted by law enforcement operations and exited skin. So they emerged in the right moment in the middle of the chaos when LockBit and Black Hat was facing this kind of problem. The second reason is, as I mentioned before, right after the Ransom Hub emerged, they leaked data of a big company that was previously published in the Black Hat TLS. So they gained a lot of attention. A lot of people started talking about Ransom Hub. So for obvious reasons, those affiliates that previously worked with Black Hat and LockBit thought that Ransom Hub could be a good group for them to move and start working with. Some additional reasons is because of the exit scams from Black Hat and also from Nosecape, Ransom Hub allow affiliates to use their own crypto wallets. So affiliates somehow felt like they could trust Ransom Hub because probably they would not steal their money since the payment, the Ransom payment was received right in the affiliates' crypto wallets. Also because the affiliates had to pay only 10% of fee for the Ransom Hub group. As you know, every time you join a Ransom Hub as a service operation, all the money that you get from the victims, you need to give like 10%, 20% of that payment to the Ransom Hub as a service group that provide the resources to the affiliates. And in case of Ransom Hub, affiliates had to pay only 10% as a fee. So it was at that time, their lowest fee I've ever seen from a Ransom group. And for obvious reasons, a lot of affiliates moved to Ransom Hub because they wanted to gain a lot of money and pay as less as they could. And I think there is something else like I've heard from a lot of Ransom Hub affiliates that the ransomware was good. The ransomware was fast. It had some cool features like that one I mentioned. They were able to encrypt data via SFTP and so on and so on. And the last thing I would like to say, why Ransom Hub became such a big Ransom as a service operation and could recruit a lot of criminals is because they created a narrative based on what the Ransom Hub admin called Lockbeat and Black Hat mistakes. So all that stuff about exit scam, the problems that Lockbeat faced because of the law enforcement operation and so on and so on. So the Ransom Hub admin posted a lot of stuff in the ramp forum talking about their mistakes and said like, look, you will not face this kind of problem with us. We are a great group and we will not make such mistakes like those that Lockbeat and Black Hat did. So I think that's one of the reasons why they became such a big group. One of many reasons it seems that this franchise model is really working out for Ransom Hub. So Pietro, can you tell us a little bit about who were the Ransom Hub targets? Ransom Hub as their affiliates financially motivated threat actors. So they do not focus on a specific country or region or industry. But because of the law enforcement operations that happened in the last year and late in 2023 that affected Black Hat, I've noticed that a lot of Ransom and affiliates started attacking critical infrastructure like the healthcare hospitals and these kind of organizations. So the same happened with the Ransom Hub. The amount of organization, healthcare organization that they attacked was really impressive because they believed, the affiliates believed that by attacking critical infrastructure the likelihood for the victims to pay the ransom was much higher. So that's why nowadays we see a lot of attacks against the healthcare organization and this kind of company. As most of the Ransom Hub as a service groups, they did not allow affiliates to attack countries like Russia, Ukraine and all of those countries that were part of Soviet Union. And also they didn't allow affiliates to attack North Korea, Cuba and some other countries. That's really hard to explain why they do not attack these countries but maybe there are some political reasons why they do not do it. But Ransom and groups admins do not have any control of what affiliates we attack. So they can have these rules but an affiliates can eventually attack a Russian company or attack a company in Brazil if they do not allow it to attack Brazil for example. Killing for example has the same very similar rule. So killing does not allow their affiliates to attack Briggs country but they may eventually attack a company in Briggs country. So they do not have any control of it and the Ransom can be run in any computer so they do not check languages, the country of that IP address of the victim. So yeah even though they have rules they do not have any control of the affiliates. Yeah I suppose there are more guidelines at this point than rules and really interesting to see them targeting critical infrastructure and healthcare. So talk to us a little bit about the impact from Ransom Hub. A lot of people may know some threat actors like those involved with the scattered spider and some other big groups joined Ransom Hub. In addition to the amount of companies that they published in the DLS they attacked really big companies. So I think that the impact that Ransom Hub made in the companies all over the world was really big. And where are Ransom Hub today? That's a hard question to answer. There are some theories that Ransom Hub may have joined Dragon Force. A lot of people know that Dragon Force advertised something that they called Ransom Hub Cartel. Even though that's not the first time that we see this kind of stuff, sometime ago in 2021 they also tried to do the same like to create a Ransom Hub Cartel and work together. But even though there is such a theory that Ransom Hub may have joined Dragon Force or even that Dragon Force attacked Ransom Hub I do not think that none of them is true. The truth is that there is no evidence of what happened to Ransom Hub. Some criminals think that Dragon Force may be a rebrand of Ransom Hub. And even though Ransom Hub admin said a lot of bad things about Dragon Force on Ramp Forum, maybe it's just to create confusion so that people will not think that Dragon Force is not a rebrand of Ransom Hub. There is no evidence of what happened to Ransom Hub. If someone did take them down, who do you think that would have been? As I mentioned, some people think that Dragon Force attacked Ransom Hub because there are some evidence that Dragon Force already attacked some other Ransom Groups. But there are some interesting information that we found in the Ransom Hub Affiliate Panel. The admin of Ransom Hub reported at least three of what they call technical issues, incidents in the infrastructure. The admin didn't mention about any attack, any fantastic exploitation of vulnerability or something like that. But that's very strange, even though we do not know who did that, either it was Glow Enforcement or maybe Dragon Force or the Ransom Group. But in one of the technical issues that the admin mentioned in the Affiliate Panel, he said that those who were trying to exploit their system, their Affiliate Panel, gained access to some decryptors. So he said that they were working on an update of their Affiliate Panel and the developer did some things wrong and it allowed those who were trying to exploit the Affiliate Panel to gain access to some decryptors. The admin said that it didn't impact all the affiliates. I mean, those who gained access to the decryptors didn't get all the decryptors, but only part of it. But that was something that was reported in the Affiliate Panel that was very strange. So maybe Dragon Force, who knows. So what does this mean for the businesses that were waiting on a decryptor? They paid their money, they're waiting for the decryptor, what do they do now? Yeah, as long as I know that there's no decryptor, you know that there is a project called no more ransom, no law enforcement and security companies upload some decryptors. But as long as I know there is no decryptor for the ransom hub, they just disappeared. Recently, countries international said that they're going to close the project. And they told their victims that, look, you can message us and we will give you, we will provide you with the decryptors. But it didn't happen with the ransom hub. So if there is no decryptor and those companies who were attacked do not have any backup, that's really hard to recover the data. Yeah, maybe there's nothing to do unless you have backup. The ransomware marketplace as a whole, you know, how are these groups orchestrating hostile takeovers? You can say even more fragmented because of a lot of stuff that happened that I mentioned here really, law enforcement operations, exit scams and so on and so on. So now we see a very fragmented that it was a really very fragmented wrestling landscape. But now it's even more fragmented wrestling landscape. So affiliates are living big groups like Keylin and Dragonforce. Some of them do not trust what they call big groups because they believe that in the future, they may exit scam like Black Hat did, like Nosecape did. So they are living these big groups and they are creating their own wrestling operation. Some of them are like wrestling as a service. Some of them are like private groups, so very close. So they allow only those that they know to join their operation. So I think that's the kind of thing we deal with right now, very fragmented but a lot of groups, a lot of uncertainty and this kind of thing. How do people move from one group to the other? Is there like, you know, a jobs board or is it people what's up in each other? It depends. I do not think that they move to the group that offer the best resources, like the best wrestler, the group that has the best features. Sometimes they move to a group because their friends work with some specific groups, or because they got some good recommendations. Even though the wrestler is not good, they have some problems, but they get some recommendations of some other threat actors. In addition to that, I think it also depends on the, let's say, propaganda that wrestling groups make on open sources like Twitter or on underground forums like RIMP. For example, now if you go and access the RIMP forum, you will see some advertisements of NOVA, which is somehow a new wrestling group, and also some advertisements of Killing. They try to make this propaganda. In addition to advertisement, they make some comments on some partnership problems to say, "Look, we have this group. We have these resources. Join us. We are ready to help you." Yeah, a little bit of some recommendations from criminals, a little bit of some propaganda that they see on underground forums. Yeah, that's how they move. Thanks, Pietro. They really sound like businesses trying to scale themselves. Employees going where their friends are working. Now that Ransom Hub has disappeared, did businesses still be concerned? Yeah, sure. Ransom Hub is just Ransom as a service provider. Those involved with Ransom Hub do not conduct any intrusion. Those who conduct intrusion, the affiliates. It doesn't matter if it's Ransom Hub, Killing, NOVA, Lockpit, it really doesn't matter. That's why companies should care about identifying, attributing the intrusion to the affiliates, understanding their techniques. Those who worked with Ransom Hub, some of them, and I know that they moved to Killing, for example. So they're still there using the same techniques, very similar modus operandi, the same tools. That's why they should be aware and be concerned. And I think that's a really key point that you brought up about the affiliates conducting the attacks, the overlaps in the tactics, techniques, and procedures. So when you look at it from a business perspective, impacted by Ransom Hub or similar groups, what are the common weaknesses that you see that could be avoided? You should patch everything which is vulnerable, of course. But especially devices that provide SSL, VPN, and web-based applications like RD-Web, C-Tricks, and stuff like that. Because usually they gain initial access by exploiting generabilities in such devices, especially SSL VPNs. But in addition to that, things that the first time we heard about Ransom as a service and partnership programs and affiliates, they use very similar techniques. So you should avoid public-facing RDPs and remote services. So what should be available on the internet is only the VPN. So you should connect to the VPN and also you connect to the VPN, you gain access to the resources of your company. RDP windows should not, in my humble opinion, be available on the internet. Otherwise, they view brute force, they will try to exploit generabilities in this kind of service. Also, the lack of two-factor authentication. So they perform a lot of brute force based on very weak passwords. So if you do not have two-factor authentication, that's a problem. And in addition to that, we see very bad password policies. So they have some word lists that they use to conduct brute force with passwords like admin, admin, admin, one, two, three. So you should not allow such a password. So the weak password and bad password policies, very serious problem. They also, I think that there's one thing that should be avoided, which is having a workstation and all of the servers in the same network. If you do it, if you do not use VLAN, for example, when criminals gain access to your network, you see everything that will be really easy to do some lateral movement. Use a VPN, please do it and do not put all the servers and workstation together. What else I think should be avoided? Unpatched, really old vulnerabilities. So I've heard a lot about some hackers that they could do some privilege escalation because they could exploit some old vulnerabilities on Windows. So that's the kind of stuff you should avoid. The lack of offline backup. You may have backup, but if it's connected to your network, the contractors may eventually gain access to your backup and also encrypt your backup. So that's why when they are talking about a successful attack, what they mean by that is that backup should be either encrypted or deleted. You should have offline backup. Yeah, I think that's all. So from a defender perspective, is there an overlap in the TTPs that they use from different RAS operators? Since the first time we see this kind of ransomware server stuff, they keep using the same techniques. I'm not saying that nothing changed. Of course, things change, but they're doing the same like brute forcing RDP servers, SSL VPNs. They will always try to exploit vulnerabilities, especially SSL VPNs. They will try to gain access, to gain initial access to the companies as fast as they can and as easy as they can because they want to do everything fast, to get money fast. If you see a vulnerability in the SSL VPN device, for example, and they can exploit by exploiting some path traversal or any vulnerability that can lead to remote code execution or they can upload web shell, they will do it. Because that's easy to hack, and as it's easy to hack, that should be better. And in addition to that, we see a lot of intrusions where affiliates gain access via valid accounts. So it doesn't matter the source. Sometimes the valid accounts is available on telegram or underground forums because someone decided to share the stereo logs. So you will see initial access brokers getting those data and selling on underground forums. You will see that they may eventually buy some credentials, some valid accounts or marketplaces. So valid accounts is a very serious problem that they keep using this technique. Talking a lot about threat actors, not only a scattered spider, but encrypt hub, for example, and some affiliates of Inc. that have been conducting intrusions and gain initial access through social engineering, like vision, email vision, and events mission. So that's a very common technique that they use. In addition to that, we see, like in the post-exploitations, they dump the hashes, they dump Kerberos tickets. They will try to use techniques like pass the hash, pass the ticket. They will use vulnerable drivers to try to queue some EDR solutions and some other antiviruses. So that's the kind of technique that we see in intrusions from affiliates of ransomware as a service groups. Excellent. Thanks a lot, Pedro. When I look at the ransomware landscape, we have the ransomware as a service operators providing the tools, providing the scalability, and we have the affiliates that are actually conducting these attacks against organization. What do you think should or could be done speaking specifically about the affiliates? I think one of the most important things is to understand the mindset of criminals, and also to understand the TTPs. As you said, there are some overlaps, so we should understand what the common techniques that they use, what kind of tools that they usually use, like we see a lot of PSSAC, we see a lot of Mimicats, we see a lot of Bloodhound, Trexploits, Windows Domain. So that's really important to understand the common techniques that we see in intrusions from the affiliates and create detection rules based on the behavior of the tools and the techniques that they use. From the Trex Intelligence perspective, I believe that's really important to conduct a human intelligence. What I mean by that? We should get information from the affiliates. We should infiltrate the groups because we should know about the vulnerabilities, about the resources that they use, their capabilities before they attack a company. We should understand how they think, how they choose a victim, why they exploit a specific vulnerability and stuff like that. That's really important to be a lot of steps ahead of the criminals, and we should not be afraid of them. They should be afraid of us. Speaking about the future, you talked about gaining access, gaining knowledge, understanding your adversary. Given the disappearance and the shifts in the ransomware marketplace, what signs are you watching for? In the last blog we published in the GroupABE blog, we noticed that the amount of companies that were published in the Killing DLS increased in the last three months. It happened right after the Brassel Hub disappeared. Maybe we have information that some affiliates that previously worked with Brassel Hub moved to Killing. Of course, we do not have full visibility about all their affiliates because Brassel Hub is not working anymore, or at least not under this brand. I think that affiliates will join Killing, will join Dragonforce because they are big and known ransomware as a service groups, or they may eventually create their own ransomware as a service group. I can give you an example. The Van Helsing ransomware as a service group was a group created by two affiliates that worked with the Brassel Hub. They do not trust, because a lot of things that happened, they do not trust big groups. They may eventually join big groups like Dragonforce and Killing, but they may create their own ransomware as a service and private ransomware groups. That's why I'm saying that the Brasselware landscape, we have an even more fragmented scenario. That's really hard to make attribution during incident response, collecting evidence in incident response and making attribution because of all of this stuff. We leave them with a fragmented scenario. Nick, you work with a lot of customers that get impacted in ransomware attacks. What sorts of things should they be doing to protect themselves? Listening to Pietro, he had a lot of great insights. I think it's not a matter of if, but when we will be attacked as a business from ransomware operators, from other APT groups, whoever it might be. It all comes down, in my opinion, to a few different categories. One is about understanding your adversaries, so collecting information either from OSIN sources or from private companies like Group IB to really understand who are the adversaries that can attack me, what are the overlapping tactics, techniques and procedures that they may use, and then making sure that we have the right tools in place to defend against it. Pietro spoke a lot about the overlapping vulnerabilities that ransomware groups will employ to try and target different organizations. Having an attack surface management capability that ingests the vulnerability intelligence to passively scan the external infrastructure or actively scan the infrastructure on the external makes sense to make sure those gaps are plugged before a ransomware group or affiliate will try to actually attack the organization. Pietro mentioned also that external remote services for employees is one of the primary entry points. Having different OTP enforced for MFA, for remote services, and having really strong identity access management solutions to make sure only your employees are accessing different services rather than external affiliates, for example. I think definitely having the right tools in place. Pietro had a lot of great points about the overlapping tactics, techniques and procedures. Knowing what those are and making sure you have the right tools in place. More importantly, I think it's to be prepared and not just from a technical perspective, but from a business perspective. What are we going to do as a business when and if this happens? How is our PR team going to react? How is our board of directors going to react? Really running those simulations, understanding how different important critical pieces of the business may react during the scenario is critically important. So, yeah, definitely having those yearly preparations for this type of incident would be critical. Awesome. Thanks, Nick. Well, that's just about all we have time for this week, Pietro. Thanks very much for joining us. It's been a pleasure having you on as a guest. Thanks, Gary and Nick for having me here. Cheers, Pietro. Thanks, man. We'll see you again next time. Your data is valuable and it's under attack. Cyber espionage groups, financially motivated threat actors, ransomware attackers and other criminal enterprises are on the rise. Working in secrecy to dismantle security perimeters, they spread like a virus through the web, stoking geopolitical tensions, holding businesses to ransom and flooding criminal marketplaces with sensitive information. These groups thrive in secrecy now more than ever. Knowing who your adversaries are is critical. So, join us as we ask who's behind the world's most prolific cyber criminal groups? What are their tactics, their motivations and their impact? Who are the world's masked actors? Masked actors is an independent podcast from GroupIB, a leading voice in the fight against cybercrime. The threat landscape evolves quickly, but all information was correct at the time of recording and based on GroupIB's high-tech crime trends report 2025. Join in the conversation online using the hashtag masked actors and don't forget to subscribe so you don't miss an episode. Thanks for listening. See you next time as we uncover more of the world's top masked actors.

Podcast Summary

Key Points:

  1. Ransom Hub, a major ransomware group, mysteriously disappeared overnight, leaving questions about the ransomware marketplace.
  2. Ransom Hub's origins are linked to Black Cat, offering ransomware-as-a-service with unique features like SFTP data encryption.
  3. Ransom Hub targeted various sectors, especially critical infrastructure like healthcare organizations, relying on affiliates for attacks.

Summary:

The transcription discusses the sudden disappearance of the ransomware group Ransom Hub, known for its extensive operations and unique features like SFTP data encryption. The origin of Ransom Hub is speculated to be linked to Black Cat, with commonalities in their operations. The group targeted critical infrastructure, especially healthcare organizations, to increase ransom payment likelihood.

Affiliates played a crucial role in carrying out attacks on behalf of Ransom Hub. The impact of Ransom Hub on businesses globally was significant, and its sudden disappearance has led to uncertainty in the ransomware marketplace. Recommendations for businesses to avoid ransomware attacks include patching vulnerable devices, avoiding weak passwords, implementing two-factor authentication, and segregating servers and workstations.

The landscape of ransomware groups has become more fragmented, with affiliates switching between groups based on recommendations, features, and propaganda. The concerns for businesses remain high, as the affiliates conducting attacks may continue operations with similar tactics and tools even after Ransom Hub's disappearance.

FAQs

The emergence of Ransom Hub raised questions about the ransomware marketplace and the fate of the cyber criminal group.

Ransom Hub attracted affiliates with lower fees, unique ransomware features, and a narrative emphasizing trust and reliability.

Ransom Hub targeted financially motivated threat actors, including healthcare organizations and critical infrastructure.

Ransom Hub made a significant impact by targeting big companies and joining hostile groups, leaving victims without decryptors.

Threat actors often move based on recommendations from peers, propaganda on underground forums, and perceived trustworthiness of the groups.

Businesses should remain vigilant as affiliates of Ransom Hub may continue attacks using similar tactics and tools.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.