RansomHouse
0 incidentes
0 paises
0 sectores
ransomware RU Ultimo: -
Aliases: Jolly Scorpius, "AMD", se asocia con dominios como techcrunch
RansomHouse is a cybercrime operation that emerged in late 2021, initially distinguishing itself by specializing in data exfiltration and extortion rather than encryption, portraying itself as a 'professional mediator' exposing security flaws in victim organizations, a facade for financial gain. The group has since evolved to incorporate encryption, particularly targeting VMware ESXi environments, and operates under a Ransomware-as-a-Service (RaaS) model with a clear division of labor between operators and affiliates. While unconfirmed, the group is believed to originate from Russia, with evidence suggesting Russian-speaking actors and alignment, as indicated by C2 infrastructure and support from pro-Russian media. RansomHouse is also tracked by some researchers under the alias Jolly Scorpius and has been linked to, or reused tools associated with, other groups like White Rabbit and Mario ESXi.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
Paises objetivo (OSINT)
United Arab Emirates
Argentina
Austria
AustraliaAruba
Azerbaijan
Belgium
Bulgaria
Brazil
Canada
Sectores objetivo (OSINT)
Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir Transportation