The SunCrypt ransomware operation has leaked data allegedly stolen from UHNJ in a September ransomware attack. SunCrypt is a ransomware operation that began its activities in October 2019.
SUNCRYPT
SunCrypt is a ransomware family and ransomware-as-a-service operation active from approximately October 2019 and prominent in 2020.
Profile source: Mallory opens in a new tabSUNCRYPT
Family profile
SunCrypt is a ransomware family and ransomware-as-a-service operation active from approximately October 2019 and prominent in 2020. Early variants were written in Go and targeted Windows systems; later variants were implemented in C/C++. SunCrypt encrypts files on local volumes and network shares, while maintaining exclusions intended to preserve operating-system functionality. It leaves ransom instructions directing victims to a Tor-based negotiation service and has used a dedicated leak site to threaten publication of stolen victim data.
SunCrypt adopted double extortion by combining encryption with data theft and public-leak threats, and was an early user of triple extortion, adding distributed-denial-of-service attacks against victims when negotiations stalled. The operation has been associated with a small, closed affiliate program. Technical analysis found substantial code overlap between an early SunCrypt variant and QNAPCrypt/eCh0raix, although the operations were assessed as likely run by separate actors.
Later SunCrypt variants added termination of processes and services that may lock files, host-cleanup behavior, event-log clearing, and self-deletion following encryption. SunCrypt has affected organizations including healthcare entities, and remained active at a limited visible level after its initial 2020 prominence.
Capabilities
- Ddos
- Defense Evasion
- Exfiltration
Operational record
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
SUNCRYPT in ATT&CK
17 distinct techniquesTechniques
17 techniquesReporting
Research mentioning SUNCRYPT
“Gootloader” expands its payload delivery options | SOPHOS
Attackers operating the Gootkit loader compromised legitimate websites and used SEO poisoning to lure users searching for legal document templates into downloading malicious ZIP archives. The archives contained JavaScript that, once executed, launched obfuscated PowerShell and began a multi-stage infection chain designed to avoid writing the final payload to disk. Trend Micro reported that the updated intrusion flow used registry stuffing, scheduled-task persistence, and reflective in-memory loading to reconstruct and run a fileless Cobalt Strike beacon. The campaign differed from earlier Gootkit activity by shifting from freeware-themed lures to legal-document themes and by encrypting registry-stored content with a custom text-replacement algorithm instead of Base64; in the observed case, the beacon communicated with 89.238.185.13 before the attack was interrupted.