RansomHub was the most significant ransomware threat in 2024 , with hackers targeting over 600 organizations worldwide.

Hackers behind ransomware-as-a-service (RaaS) business RansomHub are now exploiting patched security vulnerabilities in Microsoft Active Directory and the Netlogon protocol to escalate their privileges and gain unauthorized access to a victim's network domain controller.
“ RansomHub has targeted over 600 organizations worldwide, in sectors such as healthcare, finance, government, and critical infrastructure. As a result, it is the most active ransomware group for 2024 ,” analysts at Group-IB said .
See also: Chinese hackers combined RA World ransomware with spying tools
The ransomware group first appeared in February 2024, using source code associated with the now-defunct Knight (formerly Cyclops). About five months later, an updated version was released with capabilities for remote data encryption via the SFTP protocol.
It is available in several variants targeting Windows, VMware ESXi and SFTP servers. The RansomHub team is also recruiting affiliates as part of a partnership program.
In the incident analyzed by Group-IB, attackers unsuccessfully attempted to exploit a critical vulnerability affecting PAN-OS Palo Alto Networks' (CVE-2024-3400) using a public proof-of-concept (PoC) exploit. However, they were able to breach the network with a brute-force attack on the VPN service.
After initial access, the ransomware attack began, with data encryption and extraction occurring within 24 hours of the breach.
See also: Unimicron: Is Sarcoma ransomware behind the recent attack?
The attack exploited two known vulnerabilities in Active Directory (CVE-2021-42278 aka noPac) and the Netlogon protocol (CVE-2020-1472 or ZeroLogon) to seize the domain controller and conduct lateral movement in the network.
"Exploitation of the aforementioned vulnerabilities allowed the attacker to gain full privileged access to the domain controller, which is the core component of a Microsoft Windows-," the researchers said.
After stealing data, the attackers behind the RansomHub ransomware prepared the environment for the final phase of the attack. They made all data inaccessible in order to force the victim to pay the ransom.
Another notable aspect of the attack is the use of PCHunter to disrupt and bypass security solutions, as well as Filezilla to extract data.
See also: Zservers Sanctioned for “Providing Assistance” to LockBit Ransomware Group
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

"The origins of the RansomHub group, its offensive operations, and its overlapping characteristics with other groups confirm the existence of a vibrant cybercrime ecosystem," the researchers said.
Ransomware protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
- Stay up to date on the latest ransomware trends and tactics used by attackers
Source: thehackernews.com
