Ransomware
RansomHub
Ransomware
4 detections found
Also known as: Cyclops, Knight, RansomHub RaaS
RansomHub was a RaaS operation that emerged in February 2024, built on source code derived from the Knight ransomware (itself a rebrand of Cyclops), and rapidly became one of the most active groups by absorbing displaced affiliates from the disrupted LockBit and ALPHV/BlackCat operations, hitting targets including Change Healthcare and Frontier Communications. Its infrastructure abruptly went dark on April 1, 2025; rival operator DragonForce claimed to have taken over its affiliate base under a 'cartel' model, while other affiliates migrated to groups such as Qilin, marking RansomHub's effective collapse as a distinct brand.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- #StopRansomware: RansomHub Ransomware — CISA/FBI/MS-ISAC/HHS
- RansomHub Rides High on Knight Ransomware Source Code — GuidePoint Security
- RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control — The Hacker News
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| suricata | ET DYN_DNS DYNAMIC_DNS Query to a *.is-a-knight .org Domain | rev 3 | 2024-06-11 |
| suricata | ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.is-a-knight .org Domain | rev 3 | 2024-06-11 |
| snort | ET INFO DYNAMIC_DNS HTTP Request to a *.is-a-knight .org Domain | rev 2 | 2023-03-02 |
| snort | ET INFO DYNAMIC_DNS Query to a *.is-a-knight .org Domain | rev 2 | 2023-03-02 |