Credential Theft
- LaZagne
- Mimikatz
- ProcDump
RansomEXX is a targeted enterprise ransomware family associated with large-scale intrusions against corporate and government organizations.
Profile source: Mallory opens in a new tabRansomExx
RansomEXX is a targeted enterprise ransomware family associated with large-scale intrusions against corporate and government organizations. It originated as Defray777/Defray and rebranded as RansomEXX in 2020, after which it became closely associated with big-game hunting operations against high-value networks. The malware has been used against both Windows and Linux systems, including Linux encryptors built to target VMware ESXi environments and other centralized enterprise infrastructure.
RansomEXX encrypts victim data using AES-256 and protects per-file keys with an embedded RSA-4096 public key. Windows and Linux variants share closely related code structure and cryptographic routines, and Linux samples have been identified as ELF builds derived from the same codebase as the Windows versions. The malware is typically customized per victim, including victim-specific naming in encrypted file extensions and ransom notes. Reported behavior on Windows includes deleting backups and shadow copies, disabling recovery features, clearing event logs, and terminating numerous processes tied to security tools, databases, remote administration, and mail services in order to maximize encryption coverage and hinder recovery.
The operation is linked to hands-on intrusions rather than indiscriminate mass deployment. Reported access vectors include compromised or purchased credentials, brute-forced remote access services, exploitation of vulnerable corporate networks, and in some cases upstream delivery through other criminal malware ecosystems such as TrickBot. After gaining access, operators have been reported to move laterally, abuse credential-dumping tools such as Mimikatz, and deploy post-exploitation frameworks such as Cobalt Strike. The group has also been associated with theft of unencrypted files prior to encryption and with leak-site extortion, making it part of the broader double-extortion ransomware trend.
RansomEXX has been repeatedly observed in attacks on large organizations and public-sector entities, including incidents affecting transportation, telecommunications, regional government, manufacturing, and technology sectors. The family is notable for maintaining Linux capability aimed at ESXi and other server workloads, reflecting the broader ransomware shift toward hypervisors and centralized virtual infrastructure where a single compromise can disrupt many systems at once. Researchers have also documented implementation flaws in at least one Linux encryptor, including failure to lock files properly during encryption, which could corrupt files and interfere with the attackers’ own decryptor.
Reported operators
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
Later in 2023, the same organization was targeted by the GOLD DUPONT threat group, which distributes the RansomExx ransomware.
ReliaQuest revealed that the RansomEXX and BianLian ransomware operations have also joined these attacks, although no ransomware payloads were successfully deployed.
Exploited software
MITRE ATT&CK
Reporting
Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.