Defray is a Windows ransomware family used in small, selectively targeted attacks against organizations in the United Kingdom and United States, including healthcare, education, manufacturing, and technology. It is associated with the DefrayX threat actor group, also tracked as Hive0091, whose malware portfolio includes PyXie and the Vatet loader.
Defray has been distributed through targeted emails carrying customized Microsoft Word attachments with executables embedded as OLE packager objects. The lures impersonated organizational representatives and used healthcare or business-related themes. Infection required the recipient to double-click the embedded executable, which dropped and launched the ransomware. Defray has also been observed as a payload delivered by a loader disguised as a legitimate Notepad++ application.
The ransomware encrypts a broad range of files, including documents, spreadsheets, databases, archives, images, source code, backups, virtual-machine data, and cryptocurrency wallet files. It preserves the original file extensions and places ransom notes throughout the infected system. Observed notes demanded $5,000 and offered email and BitMessage channels for communication and negotiation. Defray reports infection information to external command-and-control infrastructure over HTTP and HTTPS.
Defray can disable startup recovery and delete volume shadow copies to impede restoration. On Windows 7, it also monitored and terminated graphical applications, including Task Manager and web browsers; this behavior was not observed on Windows XP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Like other ransomware gangs, RansomEXX will compromise a network through purchased credentials... Once they gain access to a network... After gaining access to an administrator password, they deploy the ransomware
Like other ransomware gangs, RansomEXX will compromise a network through purchased credentials, brute-forced RDP servers, or by utilizing exploits.
After gaining access to an administrator password, they deploy the ransomware on the network and encrypt all of its devices.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware strain associated with the DefrayX group.
Observed as a secondary payload delivered by the same loader in another instance.
A previously undocumented ransomware strain distributed via malicious Microsoft Word email attachments containing embedded executables. It drops and executes payloads from the %TMP% folder, encrypts a wide range of file types, creates ransom notes such as FILES.txt and HELP.txt, communicates with external C2 servers over HTTP and HTTPS to report infection information, and may disable startup recovery and delete volume shadow copies. On Windows 7 it also monitors and kills running GUI programs such as Task Manager and browsers.
Ransomware distributed through small, selectively targeted email campaigns against organizations in the UK and US. Customized Microsoft Word attachments contain an embedded executable that requires the recipient to double-click it. Defray then executes from the temporary folder under names such as taskmgr.exe or explorer.exe, encrypts files without changing their extensions, and creates FILES.TXT and HELP.txt ransom notes demanding $5,000. It reports infection information to command-and-control infrastructure over HTTP or HTTPS. After encryption, it may disable startup recovery and delete volume shadow copies; on Windows 7, it also terminates running GUI applications. The researchers suggest it may be privately operated rather than sold or offered as ransomware-as-a-service, but this is not confirmed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.