RansomHub extortion gang linked to now-defunct Knight ransomware

Share:

Security researchers analyzing the relatively new RansomHub ransomware-as-a-service believe that it has evolved from the currently defunct Knight ransomware project.

RansomHub has a short history and operated mainly as a data theft and extortion group that sells stolen files to the highest bidder.

The gang grabbed attention in mid-April when it leaked stolen data from United Health subsidiary Change Healthcare following a BlackCat/ALPHV attack, suggesting some form of collaboration between the two.

More recently, on May 28, the international auction house Christie’s admitted it had suffered a security incident after RansomHub threatened to leak stolen data.

Knight ransomware launched in late July 2023 as a re-brand of the Cyclops operation and started breaching Windows, macOS, Linux/ESXi machines to steal data and demand a ransom.

One of the peculiarities of Knight was that it also offered affiliates an info-stealer component that could make the attacks more impactful.

In February 2024, the source code for version 3.0 of Knight ransomware put up for sale on hacker forums, the victims extortion portal went offline, and the RaaS operation went silent.

Knight ransomware sale post on RAMP forums
Knight ransomware sale post on RAMP forums
source: KELA

RansomHub’s Knight origin

Malware analysts at Symantec, part of Broadcom, found multiple similarities between the two ransomware families that point to a common origin:

  • Both ransomware families are written in Go and use Gobfuscate for obfuscation.
  • There are extensive code overlaps in the two malware payloads.
  • Both use a unique obfuscation technique where important strings are encoded with unique keys.
  • The ransom notes used by the two ransomware families are similar, with minor updates added on RansomHub.
  • Both ransomware families restart endpoints in safe mode before encryption.
  • The command-line help menus on the two families are identical, with the only difference being a ‘sleep’ command on RansomHub.
  • The sequence and method of command execution operations are the same, though RansomHub now executes them via cmd.exe.
Comparison of command-line help menus, Knight (left), RansomHub (right)
Comparison of command-line help menus, Knight (left), RansomHub (right)
Source: Symantec

The above suggests that RansomHub was likely derived from Knight, and confirms that the extortion group indeed uses a data encryptor.

Also, the time RansomHub first appeared in the cybercrime space, in February 2024, matches the Knight source code sale.

According to the researchers, it is unlikely that RansomHub is run by Knight ransomware creators. They believe that another actor purchased the Knight source code and started using it in attacks.

Since it emerged, RansomHub has grown to become one of the most prolific RaaS operations, which Symantec attributes to the gang attracting former affiliates of  the ALPHV operation, such as Notchy and Scattered Spider.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:45 am, Mar 17, 2025
weather icon 5°C
L: 5° | H: 6°
overcast clouds
Humidity: 83 %
Pressure: 1028 mb
Wind: 6 mph NE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:09 am
Sunset: 6:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
5° | 6°°C 0 mm 0% 10 mph 83 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 12 mph 69 % 1027 mb 0 mm/h
Wed Mar 19 9:00 pm
weather icon
3° | 15°°C 0 mm 0% 6 mph 82 % 1022 mb 0 mm/h
Thu Mar 20 9:00 pm
weather icon
8° | 16°°C 0 mm 0% 8 mph 74 % 1021 mb 0 mm/h
Fri Mar 21 9:00 pm
weather icon
9° | 13°°C 0.2 mm 20% 6 mph 93 % 1015 mb 0 mm/h
Today 6:00 am
weather icon
3° | 5°°C 0 mm 0% 7 mph 83 % 1028 mb 0 mm/h
Today 9:00 am
weather icon
5° | 6°°C 0 mm 0% 10 mph 76 % 1028 mb 0 mm/h
Today 12:00 pm
weather icon
7° | 8°°C 0 mm 0% 10 mph 64 % 1028 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 10 mph 56 % 1027 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 10 mph 73 % 1028 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 9 mph 76 % 1028 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 9 mph 67 % 1027 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 7 mph 69 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€76,983.89
-0.58%
Ethereum(ETH)
€1,752.81
-0.94%
Tether(USDT)
€0.92
-0.01%
XRP(XRP)
€2.18
-0.86%
Solana(SOL)
€118.59
-4.68%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.158819
-1.14%
Shiba Inu(SHIB)
€0.000012
3.78%
Pepe(PEPE)
€0.000006
-4.43%
Peanut the Squirrel(PNUT)
€0.189641
20.47%
Scroll to Top