AKO is a Windows ransomware family first observed in early 2020 and associated with enterprise-focused intrusions, especially against organizations with exposed remote access services. It is part of a broader lineage linked by multiple researchers to MedusaLocker-derived code and later overlap with ThunderX and Ranzy Locker, with evidence suggesting that AKO and ThunderX were rebranded into Ranzy Locker around October 2020. AKO has also been referenced under the name Razny in some reporting.
AKO encrypts victim files and has been associated with double-extortion operations in which data is stolen prior to encryption and victims are pressured to pay both for decryption and to prevent publication of stolen information. The operators maintained a leak site used to expose non-paying victims, and public statements attributed to the group indicate that payment for decryption and payment for deletion of stolen files were treated separately. Reporting on ransomware leak-site activity and U.S. government advisories places AKO among the ransomware families observed in attacks on sectors including education, particularly K-12 institutions during 2020.
Initial access associated with AKO has been tied at high confidence to exposed or weakly secured Remote Desktop Protocol services. Broader reporting also places AKO within an ecosystem of human-operated ransomware groups that relied on credential abuse and post-compromise deployment inside corporate networks. Technical comparisons describe AKO as a C++ ransomware family sharing code and behavioral similarities with MedusaLocker, ThunderX, AVADDON, and Ranzy, including use of RSA-backed file encryption workflows, backup and shadow-copy destruction through native Windows utilities, and network-aware operation.
AKO is best understood as both a distinct ransomware brand active in 2020 and a transitional stage in a lineage that evolved into Ranzy Locker. Its significance lies in its role in the wider shift from encryption-only extortion to data-theft-enabled ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The FBI, CISA, and MS-ISAC have received numerous reports of ransomware attacks against K-12 educational institutions. | malicious cyber actors target school computer systems, slowing access, and—in some instances—rendering the systems inaccessible for basic functions, including distance learning.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family listed among BraZZZers clients observed in the logs.
Referenced as another predecessor/successor lineage connected to Ranzy Locker through reused Tor infrastructure.
Earlier related ransomware family that shares delivery patterns and some under-the-hood elements with ThunderX and Ranzy.
Referenced in passing as another ransomware operation whose Tor sites went offline.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.