Threat actor reference

Classification follows the source dataset. Metadata is useful. It is not testimony.

Actor lineage

Global lineage directory

Overview

Government and MITRE reporting link RansomHub resources to Knight/Cyclops, while MITRE explicitly frames operator continuity as possible rather than established. This record therefore uses a code-overlap relationship, not a confirmed rebrand.

Documentary media

Known aliases

No source-supported alias is currently recorded. Malware names and actor-group names are not assumed to be equivalent.

Historical timeline

Lineage and relationships

Relationships shown from this actor's perspective
Related actor or familyRelationshipPeriodConfidenceEvidence summarySources
Knight ransomwareransomware family Code overlapsuspected · directed From February 2024 Moderate confidence

MITRE reports that RansomHub operators may have purchased and rebranded Knight resources and notes code, feature, and infrastructure overlaps. The same source does not establish that Knight's operators became RansomHub.

  • MITRE uses conditional language—“may have purchased and rebranded resources”—while documenting multiple technical overlaps.
  • The joint RansomHub advisory records the Cyclops/Knight lineage but does not independently prove operator continuity.
FBI, CISA, MS-ISAC, and HHS · MITRE ATT&CK

Predecessors

None established.

Successors

None established.

Splits and mergers

None established.

Suspected affiliate relationships

None established.

MITRE ATT&CK integration

No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.

External intelligence references

  1. #StopRansomware: RansomHub RansomwareFBI, CISA, MS-ISAC, and HHS · government advisory · primary authoritative
  2. RansomHub, Software S1212MITRE ATT&CK · MITRE ATTACK · authoritative secondary

Confidence and evidence notes

Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.

Search within this collection

Negotiation records

Filter RansomHub records

Collection: 1 records · 1 messages

RansomHub negotiation record collection
Participants Source Archive status
20240810 1 RansomHub JSON Indexed