SunCrypt is a ransomware-as-a-service operation that became prominent in 2020 and is known for combining file encryption with data-theft extortion and, in some cases, distributed denial-of-service pressure against victims. It has been described as an early adopter of triple-extortion tactics, using encryption, threats to publish stolen data on a leak site, and DDoS attacks to increase pressure during ransom negotiations. The operation maintained a dedicated leak blog and publicly exposed data from non-paying victims, including organizations in the healthcare sector. SunCrypt has been characterized as a relatively small and private RaaS with a limited affiliate circle rather than a mass-scale open program. Reporting indicates the group launched operations in late 2019 and increased activity after standing up leak infrastructure. It has also been described as having claimed association with the so-called Maze cartel, although that relationship was disputed and remains uncorroborated at high confidence. Known related names in reporting include Maze, Ragnar Locker, and Avaddon in the context of similar extortion tactics, but SunCrypt is treated as a distinct operation. Technically, SunCrypt has been observed as a DLL-based ransomware payload and in some cases installed through obfuscated PowerShell. Its malware encrypts local volumes and network shares, uses threaded encryption to improve speed, and preserves system stability through allowlists that avoid encrypting critical operating-system components. Later variants added process termination, service stopping, machine-cleanup steps to facilitate encryption, event-log wiping, and self-deletion after execution. The operation’s extortion workflow included ransom negotiation portals and a leak site used to threaten publication of stolen data. Operationally, SunCrypt has been linked to big-game ransomware behavior, targeting higher-value organizations rather than indiscriminate consumer infections. Victim reporting and public leaks show activity against healthcare and large commercial entities. In at least one reported case, a SunCrypt affiliate used DDoS attacks when negotiations stalled. The group’s dominant motivation is financial gain through ransomware extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another ransomware operation with an affiliate program; also cited in an example involving a hospital attack by an affiliate.
Referenced as among the first ransomware operators to add DDoS to extortion, i.e., triple extortion.
Referenced as a ransomware gang that used Cryptomixer to launder ransom payments.
Used DDoS attacks during stalled negotiations to pressure victims into continuing ransom discussions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.