Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators
Rehub: Russian-Language Ransomware-as-a-Service Marketplace (TL-2026-2532), also tracked as Rehub, is a medium-severity tracked intrusion set, first published 2026-09-16. It is linked to a Russia-nexus actor with medium confidence, references 3 CVEs (CVE-2024-55591, CVE-2025-32433, CVE-2025-33073), maps to 16 MITRE ATT&CK techniques (T1021, T1027, T1053.005), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2532
- Threat ID
- TL-2026-2532
- Also known as
- Rehub, ReHubCom
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-16
- Last reviewed
- 2026-09-16
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, professionalservices, health, construction, government administration, technology, criticalinfrastructure, transport
- Target regions
- North America, Europe, Asia-Pacific, Middle East & Africa, Latin America
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in Rehub: Russian-Language Ransomware-as-a-Service Marketplace
Malware and tooling: Anubis Ransomware, Chaos, DEVMAN, DragonForce, LockBit, Zlader, anubis, lockbit5, the gentlemen, AnyDesk, CertiHound, GoodSync
Rehub (ReHubCom) is a Russian-language cybercrime forum founded August 10, 2025 by a former XSS moderator that has grown to 8,300+ active users and become one of the primary landing zones for ransomware operators displaced by the FBI's January 28, 2026 seizure of the RAMP forum. It now hosts multiple active RaaS programs -- DragonForce (assessed primary sponsor), The Gentlemen, CHAOS, Anubis, LockBit, and DevMan -- alongside initial-access brokerage, carding, and AI-enabled fraud discussion.
How Rehub: Russian-Language Ransomware-as-a-Service Marketplace works
Rehub emerged from the collapse of the two-decade Russian-language cybercrime forum ecosystem. XSS.is, the dominant forum since the DaMaGeLaB era, was seized on July 22-23, 2025 by French and Ukrainian police (Operation Ratatouille, led by JUNALCO with SBU support) after a four-year investigation, resulting in the arrest of a 38-year-old administrator in Kyiv who Europol says earned over EUR 7 million as a trusted escrow middleman. Former XSS moderators launched a successor forum, DamageLib, on August 1, 2025, retaining roughly two-thirds of XSS's ~50,000 membership but with markedly lower engagement, amid member suspicion that the admin handle may be law-enforcement-controlled. A separate former XSS moderator launched Rehub (ReHubCom) on August 10, 2025 as a lower-friction, structured marketplace with tiered paid membership (free entry under a zero-trust policy added mid-April 2026; Premium/Gold at $100/year; Patron/Pink at $5,000/year) and dedicated forum sections for technical discussion, programming, a leaked-data/utility library, a 'Supermarket' for ransomware affiliate programs and stolen financial data, and an arbitration system with a scammer black list.
Rehub's significance sharpened after the FBI, working with the U.S. Attorney's Office for the Southern District of Florida and DOJ CCIPS, seized the RAMP (RAMP4U, ramp4u.io) forum's clearnet and Tor infrastructure on January 28, 2026. RAMP had operated since July 12, 2021 -- founded by Mikhail Matveev ('Orange') from the remnants of the Babuk operation and later run by an administrator using the handle 'Stallman' -- as a dedicated safe haven for ransomware discussion after XSS and Exploit.in banned it post-Colonial Pipeline, hosting Conti, ALPHV/BlackCat, Qilin, RansomHub, AvosLocker, and other affiliate programs plus access brokers selling government and critical-infrastructure network entry. The seizure gave the FBI access to member emails, IPs, and private messages, and rather than consolidating around one successor, displaced operators fragmented across two platform types: T1erOne, a gated forum requiring reputation vetting or a ~$450-500 entry fee that emerged in early February 2026, and Rehub, whose lower barrier to entry absorbed affiliates, initial-access brokers, and general forum regulars. DragonForce joined Rehub the same day RAMP went dark, an opportunistic migration; LockBit and The Gentlemen had maintained a presence on Rehub since September 2025, predating the RAMP disruption.
By July 2026, Flashpoint assessed Rehub at over 8,300 active users, ~15,000 posts, and nearly 3,000 threads, with DragonForce holding a permanent home-page banner as the forum's primary sponsor or partner. The other RaaS operations advertised on the forum are independently well-documented and dangerous: DragonForce (RaaS since late 2023, built on leaked LockBit 3.0/Conti code, 645+ claimed victims across 65 countries by end of August 2026, and a Go-based Microsoft-Teams-relay backdoor named Backdoor.Turn); The Gentlemen (active since July 2025, the most active RaaS operation of Q2 2026 with ~332 published victims in the first five months of the year, exploiting FortiOS and Erlang/OTP SSH CVEs and NTLM relay for initial access/lateral movement, using a large offensive tool suite including NetExec, CertiHound, and MANSPIDER, and suffering its own backend 'Rocket Database' leak in May 2026 that exposed admin and affiliate TOX IDs); CHAOS (assessed with moderate confidence to be operated by former BlackSuit/Royal members, using email-bombing and Quick-Assist vishing for initial access, RMM tools for persistence, and GoodSync disguised as a legitimate binary for exfiltration); Anubis (RaaS since December 2024 offering encryption, data-theft-only, or hybrid extortion splits, notable for an optional /WIPEMODE destructive wiper that zeroes file contents beyond recovery); LockBit (revived as LockBit 5.0 in September 2025 post-Operation Cronos, cross-platform Windows/Linux/ESXi payloads, 335+ claimed victims across 68 countries by August 2026); and DevMan (emerged April 2025 from the DragonForce/Conti lineage, a closed multi-RaaS-affiliate operation targeting APAC/African mid-market and critical-infrastructure organizations, 116+ compromised organizations). Beyond ransomware, the hunt rationale notes Rehub's Technical section hosts AI-jailbreaking and deepfake social-engineering discussion, and its Supermarket section trades network access, carding data, and forged documents -- positioning the forum as general-purpose criminal infrastructure rather than a single-actor threat. For defenders, Rehub itself is not an intrusion vector; its significance is as durable coordination infrastructure that keeps the affiliate pool, tooling, and initial-access supply chain feeding into DragonForce, The Gentlemen, CHAOS, Anubis, LockBit, and DevMan intrusions operational despite law-enforcement pressure on RAMP and XSS.
MITRE ATT&CK techniques used in TL-2026-2532
Lateral Movement
Stealth
T1027 Obfuscated Files or Information
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Discovery
Execution
T1059.001 PowerShell; T1204.002 Malicious File
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment
Privilege Escalation
T1134.002 Create Process with Token
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery
stealth
T1574.011 Services Registry Permissions Weakness
defense-impairment
Remediation for Rehub: Russian-Language Ransomware-as-a-Service Marketplace
Patches
- Apply Fortinet patches for CVE-2024-55591 (FortiOS/FortiProxy authentication bypass)
- Apply Erlang/OTP patches for CVE-2025-32433 (SSH pre-authentication RCE)
- Apply Microsoft guidance/patches mitigating CVE-2025-33073 (NTLM reflection/relay)
Immediate actions
- Block known DragonForce C2 IPs and Tor leak-site domains at perimeter/DNS layer
- Subscribe to dark-web forum monitoring for Rehub, T1erOne, and DamageLib chatter referencing your sector or vendors
- Hunt for Anubis's /WIPEMODE and /KEY= command-line parameters in EDR telemetry
- Audit and restrict RMM tool installs (AnyDesk, ScreenConnect, Syncro, Splashtop) to an allowlist; alert on new/unexpected installs
Workarounds
- Disable or restrict external RDP/VPN exposure (T1133) where MFA cannot be enforced
- Restrict PowerShell execution policy and enable script-block logging to catch T1059.001 abuse
- Enforce MFA and conditional access on all valid-account (T1078) remote access paths
Longer-term hardening
- Deploy EDR with tamper protection against T1562 Impair Defenses techniques used across DragonForce/Gentlemen/CHAOS intrusions
- Implement NTLM relay mitigations (SMB/LDAP signing, EPA) given The Gentlemen's use of CVE-2025-33073
- Harden Active Directory Certificate Services against CertiHound/ADCS abuse
- Establish immutable, offline backups resilient to both encryption (T1486) and destructive wiping (T1485)
CVEs associated with Rehub: Russian-Language Ransomware-as-a-Service Marketplace
Timeline of Rehub: Russian-Language Ransomware-as-a-Service Marketplace
- RAMP (Russian Anonymous Marketplace) forum founded by Mikhail Matveev ('Orange') from the infrastructure of the defunct Babuk operation, as a dedicated ransomware-discussion safe haven after XSS and Exploit.in banned the topic.
- French and Ukrainian police (Operation Ratatouille, JUNALCO with SBU) seize XSS.is and arrest a 38-year-old administrator in Kyiv after a four-year investigation; Europol estimates the suspect earned over EUR 7 million as an escrow middleman.
- Former XSS moderators launch DamageLib as a Tor-based successor forum, retaining roughly two-thirds of XSS's ~50,000 membership but with markedly lower engagement.
- Rehub (ReHubCom) founded by a separate former XSS moderator as a lower-friction, structured Russian-language marketplace for ransomware programs and stolen data.
- LockBit and The Gentlemen establish an existing presence on Rehub, predating the RAMP forum disruption.
- FBI, with the U.S. Attorney's Office (SDFL) and DOJ CCIPS, seizes the RAMP forum's clearnet (ramp4u.io) and Tor infrastructure; DragonForce joins Rehub the same day in an opportunistic migration.
- T1erOne emerges as a gated, reputation- or payment-vetted successor forum, positioning itself as an explicit ransomware-permissive alternative to Rehub's lower barrier to entry.
- Rehub implements a zero-trust registration policy for free-tier entry, alongside its existing $100/year Premium and $5,000/year Patron paid membership tiers.
- The Gentlemen's backend infrastructure ('Rocket Database') is breached and partially leaked (~16.22 GB claimed, ~44.4 MB obtained), exposing admin/affiliate TOX IDs and internal coordination channels; offered for sale by broker 'n7778' for $10,000.
- Flashpoint publishes 'Understanding Illicit Ecosystems: Inside Rehub Ransomware Marketplace,' assessing Rehub at 8,300+ active users, ~15,000 posts, and DragonForce as primary sponsor, hosting The Gentlemen, CHAOS, Anubis, LockBit, and DevMan.
Sources cited for Rehub: Russian-Language Ransomware-as-a-Service Marketplace
- Understanding Illicit Ecosystems: Inside Rehub Ransomware Marketplace
- FBI Seizes RAMP Cybercrime Forum Used By Ransomware Gangs
- Darknet forum RAMP4U seized by FBI
- The Rise and Fall of RAMP: Inside the Forum Where Ransomware Was Always Welcome
- The Post-RAMP Era: Allegations, Fragmentation, and the Rebuilding of the Ransomware Underground
- XSS Forum After Takedown: DamageLib Emerges
- Thus Spoke...The Gentlemen
- DragonForce Ransomware Attack Analysis - Targets, TTPs and IoCs
- Chaos Ransomware: RaaS Resurgence & Detection
- Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper
More in threat intel
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action
- VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Theft
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding, JADESNOW/INVISIBLEFERRET, SharkStealer)
Detection coverage for TL-2026-2532
As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2532 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2532
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.