Skip to content

RansomHouse

Ransomware Group2 claimsLast activity:

Overview

RansomHouse is a financially motivated ransomware-as-a-service operation active since late 2021. Palo Alto Networks Unit 42 tracks the operators as Jolly Scorpius and describes separate roles for the core service and affiliates: operators maintain malware, leak and negotiation infrastructure, while affiliates obtain access, move through victim networks, steal data and deploy ransomware. RansomHouse presents itself as a mediator that exposes weak corporate security, but its observed activity is a conventional extortion business built around payment pressure.

Activity and targeting

RansomHouse has claimed organizations across multiple countries and critical sectors. Unit 42 reported at least 123 entries on its data-leak site between December 2021 and December 2025 and identified effects involving health care, finance, transportation and government. Earlier Trellix and Northwave research found the United States represented about 47% of the operation’s 2023 leak-site sample, with North American and Western European organizations prominent and industrial and technology companies accounting for much of the observed activity. These counts describe the group’s public claims and should not be treated as independently verified incident totals.

The operation appears willing to pursue both encryption-backed extortion and data-theft-only demands. Trellix documented one negotiation involving encrypted systems and a decryptor and another in which payment was sought only for promised deletion of stolen data. Incident-level evidence is therefore necessary before concluding that a RansomHouse listing involved encryption, exfiltration or both.

Methods and operational characteristics

RansomHouse affiliates have used spear-phishing, other social engineering and exploitation of vulnerable public-facing systems for access, followed by reconnaissance, privilege escalation and lateral movement. Trellix documented an intrusion involving a Citrix exploit, weak domain credentials, SMB and RDP access, cloud-hosted data exfiltration and Tor-based negotiation. The operation also uses dedicated chat links, countdowns, selective disclosures and its leak site to increase pressure on victims.

A notable part of the RansomHouse toolkit targets VMware ESXi environments. The MrAgent management tool connects compromised hypervisors to attacker-controlled infrastructure, gathers host and virtual-machine information, can disable the ESXi firewall and coordinates ransomware deployment across multiple hosts. It deploys the Babuk-derived Mario encryptor against virtual-machine and backup files, allowing one compromised hypervisor to affect many hosted systems. Unit 42 found that newer Mario samples added a more complex two-key encryption process, indicating continued development through 2025.

What type of group is it?

RansomHouse is best characterized as a financially motivated RaaS and double-extortion ecosystem rather than one fixed intrusion team. Its affiliates can bring different access methods, tooling and partners, so behavior should be attributed to the service only when supported by incident-specific evidence. A 2024 FBI, CISA and Defense Cyber Crime Center advisory states that Iranian state-linked access actors worked with RansomHouse affiliates to enable encryption in exchange for a share of ransom payments. That finding documents collaboration in some operations; it does not establish that RansomHouse’s core operators are Iranian, state-sponsored or directed by a government. The reviewed sources do not publicly identify the core operators or establish their jurisdiction.

Incident claims

Karl Auto Group cyberattack disrupted Iowa dealerships

View public claim
Incident date: Source: ransomware.liveDiscovered:

Claim details

RansomHouse listed Karl Chevrolet, not Karl Auto Group, on its leak site, and the post should be described as the group’s unverified claim rather than confirmation of ransomware, data theft or the scope of any compromise. However, Karl Auto Group’s public statements described unauthorized access to company business systems and operational disruptions involving phones and computers, supporting a medium-confidence assessment that the incident extended beyond the named Karl Chevrolet dealership and affected the broader organization. The available evidence does not establish that every Karl Auto Group location or business unit was affected.

Impacted organizations

Impacted locations

Sources