Skip to main content
Skip to main content
Microsoft Security Intelligence
Published May 16, 2024 | Updated Feb 25, 2025

Ransom:Win64/Ransomhub.B

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Ransom:Win64/Ransomhub.B is a variant of RansomHub tailored for high-profile enterprise targets, specifically those using Windows Server environments, Active Directory, and cloud storage services. It is an advanced evolution of the Windows-based Ransomhub strain, incorporating stealth techniques to evade detection and persistence mechanisms to maintain control over infected machines.

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us