SunCrypt is a human-operated ransomware family and ransomware-as-a-service operation active since late 2019 that became prominent in 2020 through double- and triple-extortion campaigns. It encrypts victim files, operates a leak site to pressure nonpaying organizations by threatening publication of stolen data, and has been associated with the use of distributed denial-of-service attacks during ransom negotiations. SunCrypt has targeted enterprise environments and has affected sectors including healthcare, with reporting also indicating continued activity against high-value organizations after its peak visibility.
SunCrypt has been observed in multiple technical forms over time. Early variants included a Go-based Windows build that showed strong code-level overlap with QNAPCrypt/eCh0raix, suggesting code reuse or a shared developer lineage, while later variants were rewritten in C/C++. The malware has also been distributed as a DLL payload and, when executed, encrypts files across local volumes and network shares. It uses multithreaded encryption techniques, maintains exclusion lists to avoid destabilizing systems, and newer variants added process termination, service stopping, event-log wiping, cleanup actions, and self-deletion to improve execution and hinder response.
Operationally, SunCrypt has been linked to a small, closed affiliate model rather than a broad open program. It maintained a dedicated leak blog and was repeatedly cited as an early adopter of triple extortion, combining encryption, data-theft pressure, and DDoS coercion. Some reporting also places SunCrypt in intrusion chains where access was likely obtained through other malware or brokers, including delivery by WARPRISM and downstream deployment following Gootkit activity; there are also indications that TrickBot infections may have preceded some SunCrypt incidents. Claims of affiliation with the so-called Maze cartel were made publicly by SunCrypt representatives, but those claims were disputed, so any formal organizational relationship remains unconfirmed.
SunCrypt primarily targets Windows environments at high confidence. Although its early code lineage overlaps with ransomware used against NAS devices, the supplied facts support SunCrypt itself as a Windows-targeting ransomware family. Its observed behavior and extortion model place it among the notable 2020-era big-game ransomware operations that combined encryption with data theft and public-pressure tactics.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SunCrypt ransomware operation has leaked data allegedly stolen from UHNJ in a September ransomware attack. SunCrypt is a ransomware operation that began its activities in October 2019.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The SunCrypt Ransomware sample is installed via a heavily obfuscated PowerShell script, shown below.
The cleaning feature is activated at the end of the encryption routine, using two API calls to wipe all logs.
Of the 240 GB of data allegedly stolen from University Hospital New Jersey, the attackers have leaked a 1.7 GB archive containing over 48,000 documents.
SunCrypt was one of the early pioneers of triple extortion, including file encryption, threat to publish stolen data, and DDoS (distributed denial of service) attacks on non-paying victims. | SunCrypt continues to encrypt both local volumes and network shares
The new capabilities of the 2022 SunCrypt variant include process termination, stopping services, and wiping the machine clean for ransomware execution.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a ransomware operation with an affiliate program; also cited in an example where an affiliate attacked hospitals.
SunCrypt is a ransomware-as-a-service family linked by code reuse to QNAPCrypt. It encrypts files, steals data, presents a ransom note with victim chat capability, avoids some CIS-region victims, uses Tor-hidden-service C2 infrastructure, and in later campaigns targeted organizations including healthcare providers.
Ransomware family cited as an early adopter of triple extortion by adding DDoS attacks to encryption and data-leak threats.
Ransomware family whose affiliate used DDoS pressure tactics during stalled ransom negotiations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.