Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

RansomHouse RaaS Service Upgraded with Double Extortion Strategy that Steals and Encrypt Data

RansomHouse represents a significant development in the ransomware sector, operated by a group identified as Jolly Scorpius. This ransomware-as-a-service (RaaS) platform integrates data theft with encryption, creating dual pressure points to compel…

RansomHouse represents a significant development in the ransomware sector, operated by a group identified as Jolly Scorpius. This ransomware-as-a-service (RaaS) platform integrates data theft with encryption, creating dual pressure points to compel victims to comply with demands.

Since December 2021, RansomHouse has targeted at least 123 organizations across various critical sectors, including healthcare, finance, transportation, and government, leading to substantial financial losses and severe data breaches.

The operation is supported by a sophisticated attack chain, with roles distributed among operators, attackers, and infrastructure providers. Initial access is typically gained through spear-phishing emails or exploiting system vulnerabilities, enabling attackers to move laterally within networks to access valuable data and critical infrastructure.

Once inside, threat actors deploy specialized tools to inflict maximum damage across virtualized systems. Analysts at Palo Alto Networks have identified that RansomHouse specifically targets VMware ESXi hypervisors, allowing the encryption of numerous virtual machines simultaneously, thereby creating significant operational disruption.

RansomHouse represents a significant development in the ransomware sector, operated by a group identified as Jolly Scorpius.
Laura Mitchell · Thehackingpost

The Technical Machinery Behind RansomHouse

The RansomHouse toolkit comprises two primary components operating in conjunction. The first, MrAgent, serves as the management and deployment tool, establishing persistent connections to command-and-control servers and automating ransomware deployment within ESXi environments. It manages crucial functions such as host identification, firewall disabling, and encryption orchestration.

The second component, Mario, is an encryptor representing the operation’s latest technical enhancement. Its upgraded version implements a two-stage encryption process using both primary and secondary keys, complicating decryption efforts. This version introduces chunked processing with dynamic sizing calculations, departing from the original variant's single-pass encryption with fixed segment lengths. The enhanced version employs sparse encryption techniques, processing only specific file blocks at calculated offsets, complicating static analysis.

Mario targets virtualization-specific file extensions, such as VMDK, VMEM, VMSD, VMSN, and VSWP, as well as Veeam backup files. Encrypted files have extensions appended with "mario," resulting in filenames like ".emario."

Advertisement

Once encryption is complete, Mario provides detailed statistics, including file counts, encrypted data volumes, and processing results. The evolution from simple to sophisticated, multi-layered encryption approaches reflects ongoing enhancements in technical capabilities among ransomware actors, necessitating advanced detection and response strategies from defenders.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories