Defray is a Windows ransomware family associated with highly selective, low-volume intrusion activity rather than broad indiscriminate spam operations. It has been linked to the DefrayX threat actor cluster, also tracked as Hive0091, which has also been associated with Vatet, PyXie, and later RansomExx operations. Defray has been observed in narrowly targeted campaigns against organizations in healthcare, education, manufacturing, and technology sectors in the United Kingdom and United States.
Defray has been delivered through spearphishing emails carrying Microsoft Word documents with embedded executable objects. When a recipient launches the embedded object, the malware drops and executes a ransomware payload from a temporary directory. It encrypts files according to an internal extension list, creates ransom notes across the system and on the desktop, and demands payment for decryption. Reported behavior includes communicating with external command-and-control infrastructure over HTTP and HTTPS to report infection information, disabling startup recovery, deleting volume shadow copies, and in some cases terminating user-facing processes during encryption.
Defray has also appeared as a payload delivered by the Vatet loader in campaigns that abused trojanized open-source software to disguise malicious execution. In those cases, a modified benign-looking executable loaded an encrypted blob, decrypted a payload in memory, and delivered follow-on malware including Defray. Related reporting and actor overlap indicate a lineage or operational relationship between Defray and the later RansomExx ransomware family. Defray is best characterized as a targeted enterprise ransomware used in hands-on, curated attacks rather than commodity ransomware distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Like other ransomware gangs, RansomEXX will compromise a network through purchased credentials... Once they gain access to a network... After gaining access to an administrator password, they deploy the ransomware
Like other ransomware gangs, RansomEXX will compromise a network through purchased credentials, brute-forced RDP servers, or by utilizing exploits.
After gaining access to an administrator password, they deploy the ransomware on the network and encrypt all of its devices.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware strain associated with the DefrayX group.
Observed as a secondary payload delivered by the same loader in another instance.
A previously undocumented ransomware strain distributed via malicious Microsoft Word email attachments containing embedded executables. It drops and executes payloads from the %TMP% folder, encrypts a wide range of file types, creates ransom notes such as FILES.txt and HELP.txt, communicates with external C2 servers over HTTP and HTTPS to report infection information, and may disable startup recovery and delete volume shadow copies. On Windows 7 it also monitors and kills running GUI programs such as Task Manager and browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.