Skip to content

Lorenz

Lorenz is a human-operated ransomware family and extortion operation associated with targeted intrusions against enterprise environments worldwide.

Profile source: Mallory opens in a new tab

Lorenz

Family profile

Lorenz is a human-operated ransomware family and extortion operation associated with targeted intrusions against enterprise environments worldwide. It has been linked by multiple researchers to earlier ThunderCrypt and SZ40 code lineage, although operator continuity has not been conclusively established. Lorenz has been used in customized attacks with ransom demands commonly in the hundreds of thousands of dollars and has employed double-extortion tactics by stealing victim data before encryption and threatening public release through a dedicated leak site.

Lorenz intrusions have involved hands-on-keyboard post-compromise activity, including credential harvesting, privilege escalation to local and domain administrator access, lateral movement across Windows networks, and pre-encryption data exfiltration. Observed operator tradecraft includes use of reverse shells and tunneling utilities for pivoting, living-off-the-land commands for discovery, credential dumping from LSASS, remote tasking, and log clearing for defense evasion. In at least one investigated intrusion, the actor gained initial access by exploiting CVE-2022-29499 in a Mitel MiVoice Connect appliance, established persistence with a webshell, tunneled into the internal network, exfiltrated data over SFTP, and then used Microsoft BitLocker at scale for encryption while also deploying Lorenz ransomware to a limited number of ESXi hosts.

The malware encrypts files using symmetric encryption protected by an embedded asymmetric key and has been observed dropping HTML ransom notes and directing victims to dedicated negotiation portals. Samples have been customized per victim organization. Lorenz operators have also advertised stolen data and, in some cases, access to victim networks as part of their extortion model.

A notable implementation flaw in Lorenz’s encryption routine permanently truncates the last 48 bytes of files whose size is an exact multiple of 48 bytes, rendering those bytes unrecoverable even with an attacker-supplied decryptor. Because of this flaw and subsequent reverse engineering, partial recovery has been possible for some victims and certain file types through a public decryptor. Lorenz has primarily been associated with enterprise-focused big-game hunting operations rather than indiscriminate mass campaigns.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation

Operational record

1
YARA rules
2
Ransom notes
1
Leak sites
0 available

Exploited software

Vulnerabilities linked to Lorenz

1 CVEs

Reporting

Research mentioning Lorenz

Feb 23
Arctic Wolf

Lorenz Abuses Magnet RAM Capture | Arctic Wolf

The Lorenz ransomware operation emerged as an enterprise-focused threat using double extortion: attackers stole unencrypted data before encrypting systems, then pressured victims by publishing stolen files on a leak site and, in some cases, offering both the data and internal network access for sale. Reported ransom demands ranged from $500,000 to $700,000, with victims directed to a dedicated Tor payment portal featuring Bitcoin payment instructions and live chat. Researchers said the malware appears linked to earlier ThunderCrypt and SZ40 ransomware, though it remained unclear whether the same operators were involved or whether code had been reused. Analysis of the malware showed it uses AES encryption with an embedded RSA key, appends the .Lorenz.sz40 extension to encrypted files, and drops a ransom note named HELP_SECURITY_EVENT.html. A later breakthrough by Tesorion led to a free decryptor being added to the NoMoreRansom project, allowing recovery of some files without paying. The researchers found a flaw in Lorenz’s encryption routine that irreversibly destroys the last 48 bytes of files whose size is a multiple of 48 bytes, meaning some data remains corrupted even if decrypted, while other file types such as Microsoft Office documents, PDFs, and some images and videos can be recovered in certain cases.

May 2
Trend Micro Research

AvosLocker Ransomware Variant Abuses Driver File to Disable Antivirus, Scans for Log4shell

Jun 29
The Record Media

Free decrypter available for Lorenz ransomware | The Record from Recorded Future News

May 13
Bleeping Computer

Meet Lorenz - A new ransomware gang targeting the enterprise

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.