Skip to content

Ako

AKO is a Windows ransomware family first observed in early 2020 and associated with enterprise-focused intrusions, especially against organizations with exposed remote access services.

Profile source: Mallory opens in a new tab

Ako

Family profile

AKO is a Windows ransomware family first observed in early 2020 and associated with enterprise-focused intrusions, especially against organizations with exposed remote access services. It is part of a broader lineage linked by multiple researchers to MedusaLocker-derived code and later overlap with ThunderX and Ranzy Locker, with evidence suggesting that AKO and ThunderX were rebranded into Ranzy Locker around October 2020. AKO has also been referenced under the name Razny in some reporting.

AKO encrypts victim files and has been associated with double-extortion operations in which data is stolen prior to encryption and victims are pressured to pay both for decryption and to prevent publication of stolen information. The operators maintained a leak site used to expose non-paying victims, and public statements attributed to the group indicate that payment for decryption and payment for deletion of stolen files were treated separately. Reporting on ransomware leak-site activity and U.S. government advisories places AKO among the ransomware families observed in attacks on sectors including education, particularly K-12 institutions during 2020.

Initial access associated with AKO has been tied at high confidence to exposed or weakly secured Remote Desktop Protocol services. Broader reporting also places AKO within an ecosystem of human-operated ransomware groups that relied on credential abuse and post-compromise deployment inside corporate networks. Technical comparisons describe AKO as a C++ ransomware family sharing code and behavioral similarities with MedusaLocker, ThunderX, AVADDON, and Ranzy, including use of RSA-backed file encryption workflows, backup and shadow-copy destruction through native Windows utilities, and network-aware operation.

AKO is best understood as both a distinct ransomware brand active in 2020 and a transitional stage in a lineage that evolved into Ranzy Locker. Its significance lies in its role in the wider shift from encryption-only extortion to data-theft-enabled ransomware operations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

MITRE ATT&CK

Ako in ATT&CK

8 distinct techniques

Reporting

Research mentioning Ako

Oct 28
Picus Security

A Detailed Walkthrough of Ranzy Locker Ransomware TTPs

Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.

Sep 2
Sentinelone Labs Subdomain

Ranzy Ransomware | Better Encryption Among New Features of ThunderX Derivative - SentinelLabs

Oct 16
Bleeping Computer

ThunderX Ransomware rebrands as Ranzy Locker, adds data leak site

Oct 1
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": ThunderX, Ranzy Locker

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.