Lorenz is a ransomware family associated with a financially motivated, human-operated extortion operation first observed in February 2021. Its operators conduct customized intrusions against organizations worldwide, including healthcare, public-sector, and industrial organizations. Attacks have affected Windows environments and VMware ESXi hosts. The operation combines encryption with data theft, threatening public disclosure and offering stolen databases and compromised network access for sale. Reported ransom demands have commonly ranged from $500,000 to $700,000.
Lorenz intrusions have exploited CVE-2022-29499 in internet-facing Mitel MiVoice Connect appliances. Attackers establish persistent web shells and use reverse shells and Chisel tunnels to access internal networks. Existing backdoors have remained usable after vulnerable systems were patched, with some intrusions involving months between initial compromise and ransomware deployment. Operators perform network and Active Directory discovery, extract credentials from LSASS, obtain administrator privileges, and move laterally using tools such as CrackMapExec and RDP. Observed attacks exfiltrated data using FileZilla over SFTP and suppressed appliance logging or cleared Windows event logs to hinder investigation.
The Lorenz encryptor uses AES for file encryption and an embedded RSA key to protect the AES key. Its encryptor shares code with ThunderCrypt. In addition to deploying Lorenz ransomware, operators have used remotely scheduled PowerShell scripts to enable Microsoft BitLocker across Windows endpoints. Stolen data is used for staged extortion: operators may offer it for sale, publish password-protected archives, and ultimately release archive passwords publicly.
Tesorion released a free decryptor through the No More Ransom project in June 2021, but recovery is limited to certain files and variants. Encryption defects in analyzed versions can irreversibly discard file data or prevent successful recovery even by the attackers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“We found that the threat actors were able to exploit the CVE-2022-29499 vulnerability a week prior to the implementation of the patch.” They exploited two Mitel PHP pages to download and install a web shell that remained dormant for approximately five months before a Lorenz ransomware attack.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found that multiple POST requests to this web shell had taken place in the 48 hours prior to the detonation of Lorenz ransomware.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Human-operated ransomware used for big-game hunting and data extortion. Operators gain remote access, move laterally, seek Active Directory administrator privileges, and deploy ransomware across endpoints. Files receive the .Lorenz.sz40 extension. Operators steal data, sell databases and network access, and progressively release stolen information, including password-protected archives followed by their passwords if monetization fails. Reported ransom demands typically ranged from $500,000 to $700,000. A free decryptor has limited and disputed effectiveness; a March 2022 variant contained a bug that prevented attacker-assisted recovery, although independent decryption remained possible.
Ransomware family listed among active groups impacting industrial organizations in Q4 2023.
Ransomware used in an attack involving data exfiltration followed by encryption. Investigators found that CVE-2022-29499 had been exploited to install a PHP web shell on Mitel infrastructure before patching. The shell remained dormant for approximately five months and subsequently provided access for the ransomware attack. The ransomware binary was named VOIP.exe. Patching had removed the vulnerable pages but had not removed the existing backdoor.
Ransomware family used by the Lorenz group for double-extortion: initial access via Mitel MiVoice Connect RCE (CVE-2022-29499), persistence via a webshell, credential dumping (LSASS), data exfiltration (FileZilla/SFTP), and encryption primarily via BitLocker plus Lorenz ransomware on some ESXi hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.