Ransomhouse

Active
RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture.
207 Victims
May 31, 2021 First Discovered
Sep 1, 2026 Last Discovered
15 Days Inactive
0% Infostealer
1/3 Sites Online
Known Locations (3)
Ransomhouse ©
secxrosqawaefsio3biv2dmi2c5yunf3t7ilwf54czq3v4bi7w6mbfad.onion
©RansomHouse
xw7au5pnwtl6lozbsudkmyd32n6gnqdngitjdppybudan3x3pjgpmpid.onion
zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion
Intelligence
Victims (207)

Detailed victim list temporarily unavailable

This group has 207 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.