Skip to content

Metaencryptor

MetaEncryptor is a ransomware operation associated with enterprise intrusions and extortion activity.

Profile source: Mallory opens in a new tab

Metaencryptor

Family profile

MetaEncryptor is a ransomware operation associated with enterprise intrusions and extortion activity. It has been referenced in lineage discussions around the Sfile ransomware family and has also been observed in incidents where operators deployed the modular .NET remote access trojan CSHARP-STREAMER during post-compromise operations. Reported activity indicates a focus on corporate environments, including interest in IT service providers, with operators using remote access tooling and PowerShell-heavy tradecraft to support movement within segmented networks before or alongside ransomware deployment.

MetaEncryptor has been linked to intrusion chains in which a PowerShell loader decrypts and executes CSHARP-STREAMER in memory, using AMSI bypass techniques and obfuscated decryption logic. In observed cases, operators used the RAT’s relay capability to bridge protected network segments and relied extensively on PowerShell scripts for domain-user enumeration and other hands-on-keyboard actions rather than exclusively using the RAT’s full native module set. The associated tooling supports functions including keylogging, file transfer, relay, remote execution, and credential-oriented SMB operations, indicating a broader post-exploitation toolkit around the ransomware activity.

As a ransomware threat, MetaEncryptor is associated with data encryption and extortion against business victims. Reporting places it among lower-volume or minimally observed ransomware groups, but still relevant within the broader ecosystem of rebrands, splinters, and affiliate-driven operations. Its overlap with tooling also seen in REvil, LostTrust, and ALPHV intrusions suggests either shared service providers, malware-as-a-service relationships, or common operator ecosystems rather than a purely isolated malware lineage.

MetaEncryptor targets Windows enterprise environments and is associated with post-compromise behaviors such as in-memory execution, defense evasion through AMSI bypass, reconnaissance via scripted enumeration, and lateral movement or network pivoting through relay functionality. High-confidence reporting supports its characterization as ransomware used in targeted intrusions rather than indiscriminate commodity malware.

Capabilities

  • Defense Evasion
  • Extortion
  • Keylogging
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

Operational record

1
YARA rules
2
Leak sites
2 available

Recent claims

MITRE ATT&CK

Metaencryptor in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.