Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

May 2, 2026

ZachXBT Exposes US Law Firm Gerstein Harrow’s $71M Grab of Stolen Lazarus Funds

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»RansomHub Refines Extortion Strategy as RaaS Market Fractures
RansomHub Refines Extortion Strategy as RaaS Market Fractures
Security

RansomHub Refines Extortion Strategy as RaaS Market Fractures

February 17, 2026No Comments2 Mins Read

RansomHub has refined its extortion model and expanded affiliate recruitment efforts amid increasing volatility in the ransomware ecosystem.

Following law enforcement actions and multiple exit scams affecting major Ransomware-as-a-Service (RaaS) players, the group has positioned itself as a viable alternative for displaced affiliates.

According to a new technical analysis by Group-IB, in its affiliate panel’s News section, RansomHub outlines a pricing model based on victim revenue aimed at increasing the likelihood of ransom payments. The guidance emphasizes standard disruption tactics such as deleting Windows Shadow Copies and virtual machine snapshots to prevent recovery.

Earlier versions of the group’s Negotiation FAQ – now removed – included instructions encouraging affiliates to report incidents to regulatory bodies like GDPR, PIPL and PDPL. The aim was to increase pressure by presenting ransom payments as a lower-cost option compared to potential regulatory fines. 

Unlike some groups that avoid regulatory disclosure to preserve negotiations, RansomHub previously promoted it as a tactic. Operators initially advised against exposing victim names or data, but if talks fail, stolen data could be leaked via the group’s Data Leak Site (DLS).

Throughout late 2023 and early 2024, operations by Europol, the FBI and NCA disrupted LockBit, ALPHV and others, prompted affiliate migration to other services.

RansomHub responded by promoting favorable terms to attract new partners, including:

  • Low commission rates (initially 10%, later increased to 15%)
  • Support for personal cryptocurrency wallets
  • Full affiliate control over victim negotiations
  • Additional customization options in ransom notes

Representatives were active on RAMP forums, highlighting these features while capitalizing on the instability of rivals.

In early April 2025, RansomHub’s infrastructure experienced unplanned downtime. Shortly after, Qilin’s administrator “Haise” became active on RAMP, advertising a new ransomware version and DDoS extortion features.

See also  NexGen Energy: Bet On Uranium Bull Market With One Of The Best Miners

From February onward, Qilin’s monthly victim disclosures rose significantly, suggesting a potential influx of new affiliates, possibly from RansomHub.

Read more on this malware: Qilin Ransomware’s Sophisticated Tactics Unveiled By Experts

RansomHub and other groups continue to offer broadly similar ransomware functionality, including file encryption, process termination and backup deletion. As technical differences between families narrow, affiliate trust, communication flexibility and perceived reliability increasingly influence group success.

According to Group-IB, the recent shifts highlight a broader trend – affiliate migration and brand perception are playing a larger role in RaaS group dynamics than malware innovation alone.

For defenders, tracking these changes remains essential for anticipating threat actor behavior in an increasingly fragmented threat landscape.

Source link

Extortion Fractures market RaaS RansomHub Refines strategy

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026

Tax season fuels rise in crypto wallet scams, Kaspersky reports

May 2, 2026
Top Posts

Elon Musk Flamed NFTs on the Joe Rogan Experience (And BTC Maximalists LOVED It).

November 4, 2023

Prescient Bitcoin Whale Moves $244M in BTC to Crypto Exchange. Has BTC Price Topped?

November 4, 2023

CoinDesk 20 performance update: Solana (SOL) falls 4.2%, leading index lower

February 27, 2026

Type above and press Enter to search. Press Esc to cancel.