Ransomhouse
Also known as RansomHouse
Reports
18
First seen
Mar 19, 2026
Last seen
Aug 7, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×1×4
United States×4
Brazil×3
Japan×2
Hong Kong SAR China×1
South Africa×1
Thailand×1
Romania×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×3T1566 Phishing ×2T1068 Exploitation for Privilege Escalation ×2T1190 Exploit Public-Facing Application ×2T1003 OS Credential Dumping ×2T1562.009 Impair Defenses: Safe Mode Boot ×1T1543.003 Create or Modify System Process: Windows Service ×1T1059.003 Command and Scripting Interpreter: Windows Command Shell ×1T1489 Service Stop ×1T1078 Valid Accounts ×1T1567 Exfiltration Over Web Service ×1T1195 Supply Chain Compromise ×1
Indicators
filename ×49domain ×38ip_v4 ×34cve ×8hash_md5 ×5hash_sha256 ×1hash_sha1 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High