Ransomware Intelligence

ransomhouse

Ransomware group profile

70Victims
RussiaSource country
79Impact score
Also Known As
Jolly Scorpius

Description

RansomHouse is a cybercriminal organization that specializes in data extortion through ransomware attacks, primarily targeting organizations with unpatched vulnerabilities. They employ double extortion tactics, encrypting data while threatening to leak it if ransom demands are not met. As a Ransomware-as-a-Service group, they have gained notoriety for their sophisticated phishing campaigns and exploitation of critical network weaknesses.

Key insights

  • Employs double extortion tactics by encrypting files and threatening to leak sensitive data.
  • Specializes in exploiting unpatched vulnerabilities and deploying advanced social engineering techniques.
  • Utilizes Ransomware-as-a-Service (RaaS) model to scale operations and tailor attacks to victims.
  • Targets various sectors, including healthcare and retail, with a focus on organizations with weak cybersecurity measures.
  • Utilizes tools like MrAgent and Mario ESXi for ransomware deployment and execution.
  • Recent activities indicate a shift towards targeting smaller, less-prepared organizations.
  • Ransom demands are typically paid in cryptocurrency to maintain anonymity.

Threat Level & Status Breakdown

For ransomhouse · Based on incidents in selected period

2.6threat level
Aggressiveness7/ 10
Lethality0/ 10
Criticality0.5/ 10

Status Breakdown

Claimed100.0%70
First seenJul 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for ransomhouse in the selected period

70Total attacks
18peak in Oct
5.8avg / month
↑ 1 vs first month
JulAugSepOctNovDecJanFebMarAprMayJun05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for ransomhouse

  1. 50520639cf77df0c15cc95076fac901e3d04b708
  2. bfc9b956818efe008c2dbf621244b6dc3de8319e89b9fa83c9e412ce70f82f2c
  3. 907ddb26b0dc6ed70dfb7bfedf3e7e6f6b548aea0a5b568f1f38c007204e79f6
  4. d6d6174ec5370d8ffa8a163863544d52501813dc
  5. 26b3c1269064ba1bf2bfdcf2d3d069e939f0e54fc4189e5a5263a49e17872f2a
  6. 7e35c5a7ff185dbff35e05fa91385cbf
  7. ea6adefdd2be00d0c7072a9abe188ba9b0c9a75fa57f13a654caeaaf4c3f5fbc
  8. a97a28276e4f88134561d938f60db495
  9. d36afcfe1ae2c3e6669878e6f9310a04fb6c8af525d17c4ffa8b510459d7dd4d
  10. 01735bb47a933ae9ec470e6be737d8f646a8ec66
  11. 518544e56e8ccee401ffa1b0a01a10ce23e49ec21ec441c6c7c3951b01c1b19c
  12. 2c89a18944d3a895bd6432415546635e
  13. e078778b62796bab2d7ab2b04d6b01bf
  14. 6e39063ca953f46f1d2fe50e9934aac4d0f08855b7b6b8d8996e7790da4e2d06
  15. ade84908dde9e1fbed35f643b210a6e2ade1f7c7
  16. 60d4ed7b689f3019ed1c7d7c1a9fb4f3dd044cd20a9cb51ef0c53ed66a4f6a75
  17. b379d8f583112cad3cf60f95ab3a67fd
  18. 0fe7fcc66726f8f2daed29b807d1da3c531ec004925625855f8889950d0d24d8
  19. 10f312b172391840a62cbb8837e8d89ff4f144e05ff9b97876f2fea45ca3e7bc
  20. a90103beef6b85e3874c1b79ad22f9323a7514a8162b03e465fc45a36c69356f
  21. cad891ffdea6cdcf1fbe84ce490015f0a56b8cef7f386bc07c12adc67d6ecaaa
  22. 0dcbb7c7af77efd4a2b39f2303806fcd
  23. b27ff24870d93d651ee1d8e06276fa98
  24. b1221000f43734436ec8022caaa34b133f4581ca3ae8eccd8d57ea62573f301d
  25. 8023d01ffb7a38b582f0d598afb974ee
  26. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
  27. 0a77e537c64336f97a04020e59d17d09d459d1626a075878e2b796d1e1033038
  28. ba4d58f2c5903776fe47c92a0ec3297cc7b9c8fa16b3bf5f40b46242e7092b46
  29. bab3c87cac6db1700f0a0babaa31f5cd544961d1b9ec03fd8bcdeff837fc9755
  30. 6f53f99b0a19150d53244d691dd04e80
  31. c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
  32. 6bb0c60195d90b032a3488b50a38a797dfcf9104
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for ransomhouse

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1059

T1059

T1021

T1021

T1562

T1562

T1547

T1547

T1021.001

T1021.001

T1080

T1080

T1003

T1003

Victims(70)

CompanyDomainCountryIndustryStatusDiscovered
Prince George Countyprincegeorgecountyva.govUS United StatesGovernment & Defense
Claimed
2 days ago
Promeplapromepla.comAR ArgentinaManufacturing
Claimed
3 days ago
Ma Pak Leung Company Limitedmapakleung.comHK Hong KongOther
Claimed
11 days ago
Aegle Aviationaegleaviation.comIN IndiaTransportation
Claimed
11 days ago
Karl ChevroletUS United StatesRetail & E-Commerce
Claimed
about 2 months ago
Cybersecurity VendorNA NamibiaTechnology
Claimed
about 2 months ago
Star Energy Geothermal Salakstarenergy.co.idID IndonesiaEnergy & Utilities
Claimed
about 2 months ago
Jiangsu Zenergy Battery Technologies Group Co., Ltd.zenergy.cnCN ChinaEnergy & Utilities
Claimed
about 2 months ago
Winnitex (Americas) Limitedwinnitex.comUS United StatesManufacturing
Claimed
2 months ago
Trellix (McAfee & FireEye)trellix.comUS United StatesTechnology
Claimed
about 1 month ago
Transaction Packing Inctransactionpacking.comUS United StatesTransportation
Claimed
2 months ago
[DISCLOSED]Accelerated Services
Claimed
2 months ago
[DISCLOSED]Bioptik TechnologyTW TaiwanTechnology
Claimed
2 months ago
[DISCLOSED] Irec SasFR FranceHospitality
Claimed
3 months ago
J & N StoneUS United StatesManufacturing
Claimed
3 months ago
E&S Heating & Ventilation Ltd
Claimed
3 months ago
Irec Sasirec.frFR FranceHospitality
Claimed
3 months ago
Bioptik Technologybioptik.com.twTW TaiwanTechnology
Claimed
3 months ago
Accelerated Servicesacceleratedhvac.comUS United StatesProfessional Services
Claimed
4 months ago
Neinverneinver.comES SpainHospitality
Claimed
4 months ago

Page 1 of 4