Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

RansomHub

Ransomware 4 detections found

Also known as: Cyclops, Knight, RansomHub RaaS

RansomHub was a RaaS operation that emerged in February 2024, built on source code derived from the Knight ransomware (itself a rebrand of Cyclops), and rapidly became one of the most active groups by absorbing displaced affiliates from the disrupted LockBit and ALPHV/BlackCat operations, hitting targets including Change Healthcare and Frontier Communications. Its infrastructure abruptly went dark on April 1, 2025; rival operator DragonForce claimed to have taken over its affiliate base under a 'cartel' model, while other affiliates migrated to groups such as Qilin, marking RansomHub's effective collapse as a distinct brand.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules