{"id":3236,"date":"2025-04-12T10:00:45","date_gmt":"2025-04-12T10:00:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/12\/ransomhub-ransomware-as-a-service-facing-internal-conflict-as-affiliates-lost-access-to-chat-portals\/"},"modified":"2025-04-12T10:00:45","modified_gmt":"2025-04-12T10:00:45","slug":"ransomhub-ransomware-as-a-service-facing-internal-conflict-as-affiliates-lost-access-to-chat-portals","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/12\/ransomhub-ransomware-as-a-service-facing-internal-conflict-as-affiliates-lost-access-to-chat-portals\/","title":{"rendered":"RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals"},"content":{"rendered":"<p>    RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>RansomHub, a relatively newer player in the ransomware-as-a-service (RaaS) landscape, is experiencing significant internal turmoil after affiliates suddenly lost access to negotiation chat portals on April 1st, 2025.<\/p>\n<p>This disruption has forced affiliates to redirect victim communications to alternative platforms, including those belonging to competing ransomware groups, creating confusion in ongoing extortion attempts and potentially threaten ransom payments in progress.<\/p>\n<p>The group initially gained prominence in early 2024 by offering particularly favorable payment terms to attract skilled affiliates.<\/p>\n<p>Unlike many competitors, RansomHub implemented a business model that directed ransom payments either directly to affiliates or split them at the point of transaction, significantly reducing the risk of \u201cexit-scamming\u201d \u2013 a common problem where RaaS administrators keep entire ransoms and abandon their affiliates.<\/p>\n<p>GuidePoint Security\u2019s Research and Intelligence Team (GRIT) researchers <a href=\"https:\/\/www.guidepointsecurity.com\/blog\/ransomsnub-ransomhubs-affiliate-confusion\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the first signs of trouble on the morning of April 1st when multiple client chat portals used for ransomware negotiations suddenly went offline.<\/p>\n<p>Intelligence sharing partners confirmed similar disruptions across RansomHub\u2019s infrastructure, pointing to widespread internal conflict rather than isolated technical issues.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgcYYKadqDRaRz1BziJ68M-k7DBrxXsyUH_5vZm12fXukoZcWsQiQQPZWODDiMn3MO6rtsZU_TbpXIPlsg8xwJNMK_mKGDxC4f-KebUHt24oomHptUuQVF-aZGS9IaIrnagBTSuubXg9ndUQkN8Ili41KMVWSMegu8QE9sZvq4LELn8pe9vArmFQcYoXRA\/s16000\/DragonForce%2520demonstrates%2520an%2520alleged%2520new%2520RansomHub%2520affiliate%2520portal%2520%28Source%2520-%2520Guidepointsecurity%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">DragonForce demonstrates an alleged new RansomHub affiliate portal (Source \u2013 Guidepointsecurity)<\/figcaption><\/figure>\n<\/div>\n<p>The impact extends beyond the criminal organization itself, creating uncertainty for victims currently engaged in negotiations.<\/p>\n<p>Organizations facing <a href=\"https:\/\/cybersecuritynews.com\/evilcorp-ransomhub-working-together\/\" target=\"_blank\" rel=\"noreferrer noopener\">RansomHub<\/a> ransom notes now face additional complications, as communication channels have become unreliable and the group\u2019s ability to provide decryption tools is increasingly questionable.<\/p>\n<h2 class=\"wp-block-heading\"><strong>The DragonForce Connection<\/strong><\/h2>\n<p>Adding another layer of complexity to the situation, competing <a href=\"https:\/\/cybersecuritynews.com\/new-vanhelsingraas-attacking-linux\/\" target=\"_blank\" rel=\"noreferrer noopener\">RaaS<\/a> operator DragonForce made a public claim on April 2nd that RansomHub had \u201cdecided to move to their infrastructure\u201d under \u201ca new option from The DragonForce Ransomware Cartel\u201d.<\/p>\n<p>This announcement appeared on the RAMP forum, where it prompted immediate skepticism from users, with some questioning if RansomHub had been \u201ctaken down\u201d by DragonForce.<\/p>\n<p>The ambiguity surrounding this claim was further highlighted when DragonForce requested that RansomHub \u201cconsider [their] offer,\u201d suggesting the announcement may have been premature or possibly a form of opportunistic marketing during RansomHub\u2019s moment of vulnerability.<\/p>\n<p>Evidence of this appears, where DragonForce demonstrates what they claim to be a new RansomHub affiliate portal.<\/p>\n<p>A user named \u201cHexcat\u201d directly requesting clarity for RansomHub affiliates, underscoring the confusion prevalent among the criminal ecosystem\u2019s participants.<\/p>\n<p>This instability mirrors patterns seen in other prominent ransomware groups that collapsed due to internal conflicts, including Conti (Russia-Ukraine disagreements), Alphv (affiliate exit-scamming), and <a href=\"https:\/\/cybersecuritynews.com\/cisa-black-basta-ransomware-industries\/\" target=\"_blank\" rel=\"noreferrer noopener\">Black Basta<\/a> (targeting disputes).<\/p>\n<p><strong>Find this News Interesting! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, &amp;\u00a0<a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Instant Updates!<\/strong><\/p>\n<h3 class=\"wp-block-heading\"><strong>Also Read:<\/strong><\/h3>\n<figure class=\"wp-block-embed aligncenter is-type-wp-embed is-provider-cyber-security-news wp-block-embed-cyber-security-news\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"ydUkhG0aBU\"><p><a href=\"https:\/\/cybersecuritynews.com\/nvidias-incomplete-patch-for-critical-flaw-lets-attackers-steal-ai-model-data\/\">NVIDIA\u2019s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" title=\"\u201cNVIDIA\u2019s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data\u201d \u2014 Cyber Security News\" src=\"https:\/\/cybersecuritynews.com\/nvidias-incomplete-patch-for-critical-flaw-lets-attackers-steal-ai-model-data\/embed\/#?secret=t2Y4bVBfVo#?secret=ydUkhG0aBU\" data-secret=\"ydUkhG0aBU\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div>\n<\/figure>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ransomhub-ransomware-as-a-service-facing-internal-conflict\/\">RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ransomhub-ransomware-as-a-service-facing-internal-conflict\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals RansomHub, a relatively newer player in the ransomware-as-a-service (RaaS) landscape, is experiencing significant internal turmoil after affiliates suddenly lost access to negotiation chat portals on April 1st, 2025. This disruption has forced affiliates to redirect victim communications to alternative platforms, including those belonging [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,231,649],"tags":[130],"class_list":["post-3236","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-ransomware","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3236"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3236"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3236\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}