SUNCRYPT
SunCrypt is a ransomware family active since at least the end of 2019.
Profile source: Mallory opens in a new tabSUNCRYPT
Family profile
SunCrypt is a ransomware family active since at least the end of 2019. It operated a data leak site launched in August 2020 and is associated with double-extortion activity, with reporting also describing its use in triple extortion. In October 2020, SunCrypt operators or an affiliate used distributed denial-of-service (DDoS) attacks against a victim when ransom negotiations stalled, using the disruption to pressure payment. SunCrypt has been referenced alongside other major ransomware strains in affiliate ecosystems, including reporting that a Conti affiliate later worked with SunCrypt, Monti, and LockBit strains. Mandiant observed the PowerShell dropper WARPRISM delivering SUNCRYPT, Cobalt Strike BEACON, and MIMIKATZ, with payloads loaded directly into memory to evade endpoint detection; Mandiant also noted WARPRISM may be used by multiple groups. SunCrypt appeared among notable ransomware variants in Q3 2021 with 2.5% market share. High-confidence details in the provided content identify SunCrypt primarily as a ransomware operation known for data-leak extortion and for using DDoS as an additional coercive tactic.
Operational record
MITRE ATT&CK