← Threat Actors & APT Groups

RansomHub

Every article that identifies RansomHub as responsible for or connected to reported activity.

RansomwareThe DFIR Report·1 year ago

Hide Your RDP: Password Spray Leads to RansomHub Deployment

A password spray attack against an internet-facing RDP server in November 2024 provided initial access to a victim environment, with the threat actor using known malicious IPs to attempt logins across multiple accounts. Following successful RDP authentication hours after the initial spray attempt, the attacker proceeded to deploy RansomHub ransomware. The intrusion demonstrates the persistent threat posed by exposed remote access services and the need for defensive measures against credential-based attacks.