Skip to content

RansomExx

RansomEXX is a targeted enterprise ransomware family associated with large-scale intrusions against corporate and government organizations.

Profile source: Mallory opens in a new tab

RansomExx

Family profile

RansomEXX is a targeted enterprise ransomware family associated with large-scale intrusions against corporate and government organizations. It originated as Defray777/Defray and rebranded as RansomEXX in 2020, after which it became closely associated with big-game hunting operations against high-value networks. The malware has been used against both Windows and Linux systems, including Linux encryptors built to target VMware ESXi environments and other centralized enterprise infrastructure.

RansomEXX encrypts victim data using AES-256 and protects per-file keys with an embedded RSA-4096 public key. Windows and Linux variants share closely related code structure and cryptographic routines, and Linux samples have been identified as ELF builds derived from the same codebase as the Windows versions. The malware is typically customized per victim, including victim-specific naming in encrypted file extensions and ransom notes. Reported behavior on Windows includes deleting backups and shadow copies, disabling recovery features, clearing event logs, and terminating numerous processes tied to security tools, databases, remote administration, and mail services in order to maximize encryption coverage and hinder recovery.

The operation is linked to hands-on intrusions rather than indiscriminate mass deployment. Reported access vectors include compromised or purchased credentials, brute-forced remote access services, exploitation of vulnerable corporate networks, and in some cases upstream delivery through other criminal malware ecosystems such as TrickBot. After gaining access, operators have been reported to move laterally, abuse credential-dumping tools such as Mimikatz, and deploy post-exploitation frameworks such as Cobalt Strike. The group has also been associated with theft of unencrypted files prior to encryption and with leak-site extortion, making it part of the broader double-extortion ransomware trend.

RansomEXX has been repeatedly observed in attacks on large organizations and public-sector entities, including incidents affecting transportation, telecommunications, regional government, manufacturing, and technology sectors. The family is notable for maintaining Linux capability aimed at ESXi and other server workloads, reflecting the broader ransomware shift toward hypervisors and centralized virtual infrastructure where a single compromise can disrupt many systems at once. Researchers have also documented implementation flaws in at least one Linux encryptor, including failure to lock files properly during encryption, which could corrupt files and interfere with the attackers’ own decryptor.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Post Exploitation

Operational record

1
YARA rules
5
Ransom notes
1
Leak sites
1 available

Credential Theft

  • LaZagne
  • Mimikatz
  • ProcDump

LOLBAS

  • BCDEdit
  • Windows Event Utility (wevtutil)

Offsec

  • Cobalt Strike

Reported operators

Threat actors

3 named in public reporting
Bassterlord

Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.

Gold Dupont

Later in 2023, the same organization was targeted by the GOLD DUPONT threat group, which distributes the RansomExx ransomware.

RansomEXX

ReliaQuest revealed that the RansomEXX and BianLian ransomware operations have also joined these attacks, although no ransomware payloads were successfully deployed.

Exploited software

Vulnerabilities linked to RansomExx

6 CVEs

MITRE ATT&CK

RansomExx in ATT&CK

24 distinct techniques

Reporting

Research mentioning RansomExx

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.