Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Ransomware - FBI: RansomHub Hits Over 200 Entities Since Feb
Ransomware Attacks Latest News News & Analysis Threat Intelligence Threats and Vulnerabilities

FBI: RansomHub Hits Over 200 Entities Since Feb

ISB Staff ReporterBy ISB Staff ReporterAugust 30, 2024Updated:November 8, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

RansomHub, previously known as Cyclops and Knight, has quickly gained traction, targeting over 210 victims across US critical infrastructure sectors. This ransomware-as-a-service (RaaS) model has been active since February 2024.

These include water and wastewater, information technology, government services and facilities, healthcare and public health, emergency services, food and agriculture, financial services, commercial facilities, critical manufacturing, transportation, and communications critical infrastructure sectors.

This was revealed in a new joint Cybersecurity Advisory that was issued by the FBI, CISA, MS-ISAC, and the Department of Health and Human Services. This advisory is part of the broader #StopRansomware campaign, which aims to protect network defenders from various ransomware variants and threat actors.

The advisory highlights various tactics, techniques, and procedures (TTPs) used by RansomHub affiliates, who have recently attracted high-profile actors from other notorious ransomware variants such as LockBit and ALPHV.

How RansomHub Operates

The ransomware operates on a double-extortion model, encrypting and exfiltrating data to coerce victims into paying ransoms.

Unusually, instead of including the ransom demand in the initial attack, RansomHub directs targets to a Tor website, where they are provided with a unique client ID and instructions on how to proceed.

Depending on the affiliate, the ransom note usually gives victims between three and 90 days to cough up the ransom before the gang publishes their data on the RansomHub Tor data leak site.

To date, RansomHub has claimed many prominent victims, including Frontier Communications, Christie’s Auction House, Change Healthcare, and oil field services firm Halliburton.

Mitigations to Defend Against RansomHub Ransomware

The joint advisory issued by the FBI, CISA, MS-ISAC, and HHS outlines a comprehensive set of mitigations to protect organizations from the growing threat posed by RansomHub ransomware.

These recommendations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST), which are designed to help organizations strengthen their cybersecurity posture against the most common and impactful threats.

Network Defenders – Mitigations

CISA and NIST recommend organizations implement the following mitigations to strengthen their cybersecurity posture against threats like RansomHub:

Recovery and Backup:

  • Develop a recovery plan with multiple copies of sensitive data stored separately and securely (such as hard drive, storage device, cloud).
  • Maintain offline backups that are encrypted, immutable, and cover the entire data infrastructure.

Password Policies:

  • Enforce NIST standards for password management (8-64 characters, hashed storage, no reuse, lockouts for failed attempts, avoid frequent resets).
  • Require administrator credentials for software installation.

System and Software Updates:

  • Keep all systems, software, and firmware up to date, prioritizing patches for known vulnerabilities.

Authentication and Access Control:

  • Mandate phishing-resistant multifactor authentication (MFA) for admin accounts and standard MFA for critical services.
  • Implement network segmentation to limit ransomware spread and enforce least privilege access.

Monitoring and Detection:

  • Utilize network monitoring tools, including endpoint detection and response (EDR) systems, to detect abnormal activities.
  • Regularly audit user accounts, disable unused ports, and review domain controllers for unrecognized accounts.

Email and Script Security:

  • Enforce email security policies, disable macros by default, and consider email banners for external messages.
  • Disable hyperlinks in received emails and restrict command-line and scripting activities to prevent privilege escalation.

Additional Security Practices:

  • Implement secure logging, maintain antivirus software with real-time detection, and apply time-based access for admin accounts.

Mitigations for Software Manufacturers

CISA stresses that software manufacturers play a crucial role in mitigating security risks by embedding security into their product architecture throughout the entire software development lifecycle (SDLC). They are encouraged to make security a default feature, including mandating phishing-resistant multifactor authentication (MFA) for privileged users, instead of leaving these measures as optional.

By adopting secure-by-design principles, manufacturers can reduce vulnerabilities such as misconfigurations and weak passwords, thereby relieving customers of the burden of making additional security enhancements. These efforts align with the guidelines outlined in CISA’s “Shifting the Balance of Cybersecurity Risk” guide, encouraging manufacturers to deliver products that are secure “out of the box.”

CISA also recommends that organizations regularly test and validate their security controls against the MITRE ATT&CK for Enterprise framework. This process involves selecting ATT&CK techniques relevant to their environment, aligning and testing their security technologies against these techniques, and analyzing the performance of detection and prevention measures. By continually refining their security programs based on these assessments, organizations can ensure that their defenses remain robust against evolving threats.

ISB Staff Reporter
  • ISB Staff Reporter
    Mass Exploit Lets Attackers Install Plugins Arbitrarily
  • ISB Staff Reporter
    Cyberattacks Soar 47% Globally – Attacks on Education Increase by 73%
  • ISB Staff Reporter
    CISA Warns of Two Known Exploited Vulnerabilities
  • ISB Staff Reporter
    JFrog Becomes an AI System of Record, Debuts JFrog ML

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}