Exfiltration
- UFile
Ranzy Locker is a Windows ransomware family that emerged in late 2020 as a rebranded successor to ThunderX and has also been linked by lineage and shared infrastructure to Ako.
Profile source: Mallory opens in a new tabRanzy Locker
Ranzy Locker is a Windows ransomware family that emerged in late 2020 as a rebranded successor to ThunderX and has also been linked by lineage and shared infrastructure to Ako. It was used by financially motivated operators in intrusions against U.S. organizations across sectors including construction, academia, information technology, transportation, manufacturing, and government-related environments. By mid-2021 it had been associated with compromises of more than 30 U.S. businesses.
Ranzy Locker is operated as a double-extortion ransomware, combining file encryption with theft of sensitive data and threats to publish stolen information if victims refuse to pay. Reported pre-encryption collection objectives included customer information, personally identifiable information, and financial records. The malware encrypts files on compromised Windows systems, including servers, virtual machines, and attached network shares, and leaves ransom notes throughout affected directories. Operators also maintained a leak site and negotiation portal to pressure victims and facilitate payment discussions.
Observed initial access methods included brute-force attacks against Remote Desktop Protocol credentials, use of valid accounts over RDP, exploitation of known Microsoft Exchange Server vulnerabilities, and phishing. Post-compromise behavior included attempts at lateral movement across the victim network, discovery of mounted drives and SMB shares, enumeration of processes, and network-oriented discovery activity. Ranzy Locker also attempted to establish additional accounts in some environments.
The malware includes anti-recovery and defense-evasion behavior typical of mature ransomware operations. It deletes shadow copies and backups, disables Windows recovery features, and can terminate processes or services that keep files open in order to maximize encryption coverage. Technical reporting has also described use of Windows APIs for system interaction and anti-debugging checks. Public reporting further characterizes Ranzy Locker as an improved continuation of ThunderX after flaws in earlier ThunderX samples enabled free decryption for some victims.
MITRE ATT&CK
Reporting
Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.