RansomEXX is a targeted enterprise ransomware family associated with large-scale intrusions against corporate and government organizations. It originated as Defray777/Defray and rebranded as RansomEXX in 2020, after which it became closely associated with big-game hunting operations against high-value networks. The malware has been used against both Windows and Linux systems, including Linux encryptors built to target VMware ESXi environments and other centralized enterprise infrastructure.
RansomEXX encrypts victim data using AES-256 and protects per-file keys with an embedded RSA-4096 public key. Windows and Linux variants share closely related code structure and cryptographic routines, and Linux samples have been identified as ELF builds derived from the same codebase as the Windows versions. The malware is typically customized per victim, including victim-specific naming in encrypted file extensions and ransom notes. Reported behavior on Windows includes deleting backups and shadow copies, disabling recovery features, clearing event logs, and terminating numerous processes tied to security tools, databases, remote administration, and mail services in order to maximize encryption coverage and hinder recovery.
The operation is linked to hands-on intrusions rather than indiscriminate mass deployment. Reported access vectors include compromised or purchased credentials, brute-forced remote access services, exploitation of vulnerable corporate networks, and in some cases upstream delivery through other criminal malware ecosystems such as TrickBot. After gaining access, operators have been reported to move laterally, abuse credential-dumping tools such as Mimikatz, and deploy post-exploitation frameworks such as Cobalt Strike. The group has also been associated with theft of unencrypted files prior to encryption and with leak-site extortion, making it part of the broader double-extortion ransomware trend.
RansomEXX has been repeatedly observed in attacks on large organizations and public-sector entities, including incidents affecting transportation, telecommunications, regional government, manufacturing, and technology sectors. The family is notable for maintaining Linux capability aimed at ESXi and other server workloads, reflecting the broader ransomware shift toward hypervisors and centralized virtual infrastructure where a single compromise can disrupt many systems at once. Researchers have also documented implementation flaws in at least one Linux encryptor, including failure to lock files properly during encryption, which could corrupt files and interfere with the attackers’ own decryptor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The victims were industrial companies in Southeast Asia. To penetrate the infrastructure, the attackers exploited the CVE-2017-0144 vulnerability.
SAP NetWeaver, a cornerstone for enterprise operations across countless global organizations, faces a severe threat from a newly discovered deserialization vulnerability, CVE-2025-42980. With a CVSS score of 9.1, this flaw could enable attackers to execute arbitrary code... Threat Intelligence Active exploitation by ransomware groups, including BianLian and Ransomexx, has been observed.
Ransomware groups and Chinese advanced persistent threat (APT) groups are targeting a critical vulnerability in SAP NetWeaver... The vulnerability, tracked as CVE-2025-31324, has a CVSS score of 10 and affects NetWeaver's Visual Composer development server. Threat actors can exploit the vulnerability using remote attacks to execute arbitrary code without authentication... SAP later confirmed it as an unrestricted file upload vulnerability... allowing attackers to upload malicious files directly to the system without authorization.
Kaspersky said in a new blog post on Monday that it saw PipeMagic used alongside a RansomExx ransomware campaign. | Researchers at ESET discovered the corresponding zero-day — tracked as CVE-2025-29824 — in March. The bug impacts Windows Common Log File System Driver (CFLS)... “Once PipeMagic is running, the threat actor performs the CLFS exploit to escalate privileges before launching their ransomware,” Microsoft said.
ReliaQuest ... uncovered evidence suggesting involvement from the BianLian data extortion crew and the RansomExx ransomware family, which is traced by Microsoft under the moniker Storm-2460.
Back in January, the Jenkins team revealed a command line interface (CLI) path traversal vulnerability that could allow unauthorized attackers to read arbitrary files on its controller file system... Labeled CVE-2024-23897... And it remains under active exploitation today, according to ... CISA ... added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
Later in 2023, the same organization was targeted by the GOLD DUPONT threat group, which distributes the RansomExx ransomware.
ReliaQuest revealed that the RansomEXX and BianLian ransomware operations have also joined these attacks, although no ransomware payloads were successfully deployed.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
A November 2020 technical analysis of Pyxie RAT, a remote access trojan that often precedes Defray777/RansomEXX ransomware infections, identified several keyword searches on a victim’s network indicating an interest in the victim’s current and near future stock share price.
The AES key is encrypted by a public RSA-4096 key embedded in the Trojan’s body and appended to each encrypted file.
...очищает журналы Windows ( Application, System, Setup, Security ), используя команды: wevtutil.exe cl Application ... wevtutil.exe cl Security
When RansomExx encrypts a file, it will append an RSA encrypted decryption key to the end of each encrypted file. If a victim pays a ransom, the threat actor supplies a decryptor that can decrypt each file's encrypted decryption key and then use it to decrypt the file's contents.
Cybersecurity sources familiar with the attack told BleepingComputer that Tyler Technologies suffered an attack by the RansomExx ransomware. | This encrypted file has an extension of '.tylertech911-f1e1a2ac,' which includes Tyler Technologies' name and is the same format used in other RansomExx attacks.
Удаляет теневые копии файлов, бэкапы системы... используя команды: cipher /w %s wbadmin.exe delete catalog -quiet ... | ...отключает функции восстановления и исправления Windows на этапе загрузки... bcdedit.exe /set {default} recoveryenabled no ... schtasks.exe /Change /TN "\Microsoft\Windows\SystemRestore\SR" /disable
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison point because it can also encrypt Linux files.
Enterprise-targeting ransomware that encrypts files on Windows and Linux systems using AES-256 with RSA-4096-wrapped keys, appends victim-specific extensions, drops ransom notes, deletes shadow copies/backups, disables recovery features, clears logs, and can target vulnerable corporate networks and centralized storage.
Ransomware family associated with attacks leveraging PipeMagic as part of the deployment chain (per summary).
A ransomware family mentioned for comparison in a later intrusion against the same organization previously targeted with LockBit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.