Defray777 is a human-operated ransomware family associated with financially motivated enterprise intrusions and widely linked to the threat cluster tracked as GOLD DUPONT and PyXie. It is also closely associated with RansomEXX and RansomX; reporting indicates Defray777 evolved into or was rebranded as RansomEXX, while code analysis has also described it as an evolution of that threat. The malware has been used since at least 2018 in targeted attacks against organizations including healthcare, education, government, and technology entities, and later appeared in high-profile campaigns against large enterprises and public-sector victims.
Defray777 is notable for having standalone Windows and Linux variants, including Linux builds used against virtualization infrastructure such as VMware ESXi hosts. The Linux variant is command-line driven and encrypts files in a specified directory. In observed intrusions, operators executed Defray777 entirely in memory after deploying precursor tooling, then encrypted files on local drives and network shares before terminating. This in-memory execution pattern reduces on-disk evidence aside from encrypted data and ransom notes.
Defray777 commonly appears late in a broader intrusion chain. Initial access has been linked to trojan-delivered compromises, particularly via IcedID and Trickbot, after which operators deploy the Vatet loader, PyXie RAT or PyXie Lite, and Cobalt Strike for staging, reconnaissance, credential and document theft, and lateral preparation. Vatet has been used to load payloads into memory, while PyXie tooling has been used for host discovery, privilege and domain enumeration, sensitive-file discovery, and exfiltration prior to ransomware deployment. Cobalt Strike has been used to deliver Defray777 into memory for final encryption.
The malware is part of a broader big-game-hunting and double-extortion ecosystem. Associated operators have been reported to steal unencrypted files before encryption and use the threat of disclosure to pressure victims, including organizations involved in significant financial events. Defray777-linked activity has also been tied to targeting of Linux-based critical servers and ESXi environments to maximize operational disruption across virtualized infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
From there, they deployed Vatet, PyXie and Cobalt Strike before executing Defray777 ransomware entirely in memory. This results in encrypted files on local drives and file shares before exiting.
From there, they deployed Vatet, PyXie and Cobalt Strike before executing Defray777 ransomware entirely in memory. This results in encrypted files on local drives and file shares before exiting.
"...SPRITE SPIDER (the operators of Defray777) ... deploy Linux versions ... on ESXi hosts during BGH operations."
9 distinct techniques documented for this family, organized by ATT&CK tactic.
A November 2020 technical analysis of Pyxie RAT, a remote access trojan that often precedes Defray777/RansomEXX ransomware infections, identified several keyword searches on a victim’s network indicating an interest in the victim’s current and near future stock share price.
Cybersecurity sources familiar with the attack told BleepingComputer that Tyler Technologies suffered an attack by the RansomExx ransomware. | This encrypted file has an extension of '.tylertech911-f1e1a2ac,' which includes Tyler Technologies' name and is the same format used in other RansomExx attacks.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family referenced in connection with use of cipher.exe to clear unallocated disk sectors, a behavior intended to hinder forensic recovery of deleted files.
Linux command-line ransomware that encrypts files in a specified directory and appears to be an evolution of RansomEXX.
Earlier name of the ransomware operation later rebranded as RansomExx.
Ransomware payload ultimately executed in the Vatet/IcedID intrusion chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.