Skip to content

Sarcoma

Sarcoma is a ransomware family and ransomware-as-a-service operation first observed in October 2024 that rapidly became active in double-extortion campaigns worldwide.

Profile source: Mallory opens in a new tab

Sarcoma

Family profile

Sarcoma is a ransomware family and ransomware-as-a-service operation first observed in October 2024 that rapidly became active in double-extortion campaigns worldwide. It has been associated with attacks against high-value organizations across multiple sectors, including manufacturing, supply chains, healthcare-related entities, government-linked organizations, and other small and medium-sized enterprises. Reported victim geography includes North America, Europe, and Asia, with notable activity affecting industrial and electronics manufacturing environments.

Sarcoma supports both Windows and Linux environments. The Windows variant is written in C++ and uses hybrid encryption, combining ChaCha20 for file encryption with RSA to protect per-file or per-session symmetric material. The Linux variant implements comparable hybrid encryption logic and has been observed using functionality intended to hinder recovery in virtualized environments by removing VMware snapshots. On Windows, Sarcoma has also been observed terminating database-related processes and services before encryption to maximize file access and operational disruption.

The malware includes anti-analysis and regional evasion behavior. A documented Windows sample checks for the Uzbek keyboard layout and, if present, deletes itself and exits. Sarcoma also performs passive and active network discovery, including local network enumeration and host reachability checks, then attempts lateral movement by copying itself to reachable remote systems over SMB or native Windows networking mechanisms. Remote execution has been observed via scheduled tasks, with authentication to target systems using valid credentials or tokens.

Sarcoma operators and affiliates have been described as using double extortion, combining data theft with encryption and subsequent leak-site pressure. The group has also been linked to supply-chain-focused targeting and abuse of legitimate remote management tooling for reconnaissance and lateral movement. Reported intrusion vectors include phishing, exploitation of older vulnerabilities, and supply-chain compromise. Public reporting has also described use of RDP during post-compromise movement. Overall, Sarcoma is a fast-evolving cross-platform ransomware threat notable for disruptive encryption, data exfiltration, lateral movement capability, recovery inhibition, and extortion-driven operations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Reconnaissance

Operational record

1
YARA rules
1
Leak sites
1 available

Discovery Enum

  • Advanced IP Scanner

Reported operators

Threat actors

1 named in public reporting
Sarcoma

"Radix ... said that Sarcoma ransomware affiliates compromised its systems on June 16."

MITRE ATT&CK

Sarcoma in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.