RansomEXX is an enterprise-targeting ransomware family derived from Defray777, which emerged in 2018 and was rebranded in June 2020. It targets Windows and Linux systems, including VMware ESXi infrastructure, and is associated with the financially motivated GOLD DUPONT threat group. The ransomware affiliate Bassterlord has also worked with the operation. Victims span government, technology, manufacturing, telecommunications, healthcare, and other large organizations across multiple regions.
RansomEXX campaigns use compromised credentials, brute-forced RDP access, phishing, and exploitation of exposed applications or remote-access services to enter organizational networks. Operators use tools such as Cobalt Strike and Mimikatz for post-compromise activity, credential theft, and lateral movement before deploying ransomware with administrative privileges. Attacks combine file encryption with theft of sensitive documents and threats to publish stolen information, supporting double extortion through a dedicated leak site. TrickBot has also been used to distribute RansomEXX.
The ransomware uses AES-based file encryption with RSA protection of encryption keys, appends victim-specific extensions, and leaves customized ransom instructions. Windows variants delete shadow copies and backups, disable recovery mechanisms, clear event logs, and terminate processes associated with security software and enterprise applications. Linux encryptors target critical servers and virtualized workloads. An analyzed Linux variant failed to lock files during encryption, allowing concurrent writes to interfere with recovery by the attacker-provided decryptor. A corrective third-party decryptor addresses this specific defect but still requires the appropriate decryption key. The family has also evolved from C++ implementations to Rust-based variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Jenkins instance used by Brontoo Technology was affected by the same LFI CVE which can be leveraged to read internal code or in this case as port 22 was open, get secure shell access by reading the private keys.
The victims were industrial companies in Southeast Asia. To penetrate the infrastructure, the attackers exploited the CVE-2017-0144 vulnerability.
SAP NetWeaver, a cornerstone for enterprise operations across countless global organizations, faces a severe threat from a newly discovered deserialization vulnerability, CVE-2025-42980. With a CVSS score of 9.1, this flaw could enable attackers to execute arbitrary code... Threat Intelligence Active exploitation by ransomware groups, including BianLian and Ransomexx, has been observed.
Ransomware groups and Chinese advanced persistent threat (APT) groups are targeting a critical vulnerability in SAP NetWeaver... The vulnerability, tracked as CVE-2025-31324, has a CVSS score of 10 and affects NetWeaver's Visual Composer development server. Threat actors can exploit the vulnerability using remote attacks to execute arbitrary code without authentication... SAP later confirmed it as an unrestricted file upload vulnerability... allowing attackers to upload malicious files directly to the system without authorization.
Kaspersky said in a new blog post on Monday that it saw PipeMagic used alongside a RansomExx ransomware campaign. | Researchers at ESET discovered the corresponding zero-day — tracked as CVE-2025-29824 — in March. The bug impacts Windows Common Log File System Driver (CFLS)... “Once PipeMagic is running, the threat actor performs the CLFS exploit to escalate privileges before launching their ransomware,” Microsoft said.
ReliaQuest ... uncovered evidence suggesting involvement from the BianLian data extortion crew and the RansomExx ransomware family, which is traced by Microsoft under the moniker Storm-2460.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RansomEXX v2.0 is a sophisticated variant of the RansomEXX ransomware, known for targeting large organizations and demanding significant ransom payments.
Later in 2023, the same organization was targeted by the GOLD DUPONT threat group, which distributes the RansomExx ransomware.
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
A November 2020 technical analysis of Pyxie RAT, a remote access trojan that often precedes Defray777/RansomEXX ransomware infections, identified several keyword searches on a victim’s network indicating an interest in the victim’s current and near future stock share price.
The AES key is encrypted by a public RSA-4096 key embedded in the Trojan’s body and appended to each encrypted file.
Модифицирует следующие ключи реестра: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableConfig ... DisableSR
Отключает восстановление системы... Завершает 289 процессов, связанных с защитным ПО, серверами баз данных, программным обеспечением MSP, инструментами удаленного доступа и почтовыми серверами.
Может распространяться путём взлома через незащищенную конфигурацию RDP...
Like other ransomware gangs, RansomEXX will compromise a network through purchased credentials, brute-forced RDP servers, or by utilizing exploits.
When RansomExx encrypts a file, it will append an RSA encrypted decryption key to the end of each encrypted file. If a victim pays a ransom, the threat actor supplies a decryptor that can decrypt each file's encrypted decryption key and then use it to decrypt the file's contents.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison point because it can also encrypt Linux files.
Enterprise-targeting ransomware that encrypts files on Windows and Linux systems using AES-256 with RSA-4096-wrapped keys, appends victim-specific extensions, drops ransom notes, deletes shadow copies/backups, disables recovery features, clears logs, and can target vulnerable corporate networks and centralized storage.
Ransomware family associated with attacks leveraging PipeMagic as part of the deployment chain (per summary).
A ransomware family mentioned for comparison in a later intrusion against the same organization previously targeted with LockBit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.