RansomEXX is a cybercriminal ransomware operation that originally appeared as Defray in 2018 and rebranded as RansomEXX in June 2020. After the rebrand, the group became associated with big-game hunting against large enterprises and public-sector organizations. The operation has been linked to intrusions affecting government networks, telecommunications providers, healthcare-related regional infrastructure, and large corporate environments. Known aliases and related naming include Defray and Defray777; Microsoft has also tracked activity associated with the group as Storm-2460 in reporting tied to exploitation of SAP vulnerabilities. RansomEXX commonly combines network intrusion, lateral movement, credential abuse, data theft, and ransomware deployment. Reported access methods include exploitation of exposed vulnerabilities, use of stolen or purchased credentials, and brute-forcing remote access services. Once inside a victim environment, operators are described as moving laterally, obtaining administrator-level access, stealing sensitive unencrypted files for leverage, and then encrypting systems across the network. The group has used extortion based on stolen data in addition to file encryption. The operation has developed Linux ransomware, including encryptors aimed at VMware ESXi environments, reflecting a focus on high-impact enterprise virtualization infrastructure. Technical reporting also noted that the malware codebase was converted from C++ to Rust. A remote access trojan known as Pyxie RAT has been observed preceding some Defray777/RansomEXX incidents, and related reporting indicated victim reconnaissance that included interest in stock valuation and other financially sensitive information to strengthen extortion pressure. RansomEXX has been associated with exploitation of SAP vulnerabilities, including CVE-2025-31324, alongside other ransomware actors. Public reporting has also tied the group to attacks or suspected attacks against organizations and government entities in Brazil, Ecuador, Italy, Vietnam, and the United States, including public-sector and telecommunications victims. The actor is financially motivated and operates as a ransomware/extortion threat rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The Common Log File System (CLFS) 0-day vulnerability CVE-2025–29824 was confirmed to have been exploited by attackers associated with PLAY and Storm-2460, and according to Symantec, the vulnerability may have already fallen into the hands of multiple attackers and been exploited before it was patched.
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a cybercriminal group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324.
Referenced as a cybercrime group that previously weaponized SAP product flaws including CVE-2025-31324.
Conducting a ransomware attack and data breach against Go2Joy, with claims of releasing the complete database of the victim.
Mentioned as one of several threat actors that previously exploited SAP NetWeaver CVE-2025-31324 as a zero day.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.