Skip to content

SUNCRYPT

SunCrypt is a ransomware family and ransomware-as-a-service operation active from approximately October 2019 and prominent in 2020.

Profile source: Mallory opens in a new tab

SUNCRYPT

Family profile

SunCrypt is a ransomware family and ransomware-as-a-service operation active from approximately October 2019 and prominent in 2020. Early variants were written in Go and targeted Windows systems; later variants were implemented in C/C++. SunCrypt encrypts files on local volumes and network shares, while maintaining exclusions intended to preserve operating-system functionality. It leaves ransom instructions directing victims to a Tor-based negotiation service and has used a dedicated leak site to threaten publication of stolen victim data.

SunCrypt adopted double extortion by combining encryption with data theft and public-leak threats, and was an early user of triple extortion, adding distributed-denial-of-service attacks against victims when negotiations stalled. The operation has been associated with a small, closed affiliate program. Technical analysis found substantial code overlap between an early SunCrypt variant and QNAPCrypt/eCh0raix, although the operations were assessed as likely run by separate actors.

Later SunCrypt variants added termination of processes and services that may lock files, host-cleanup behavior, event-log clearing, and self-deletion following encryption. SunCrypt has affected organizations including healthcare entities, and remained active at a limited visible level after its initial 2020 prominence.

Capabilities

  • Ddos
  • Defense Evasion
  • Exfiltration

Operational record

1
YARA rules
1
Ransom notes
2
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Maze Cartel

The SunCrypt ransomware operation has leaked data allegedly stolen from UHNJ in a September ransomware attack. SunCrypt is a ransomware operation that began its activities in October 2019.

MITRE ATT&CK

SUNCRYPT in ATT&CK

17 distinct techniques

Reporting

Research mentioning SUNCRYPT

Jan 1
Sophos Threat Research

“Gootloader” expands its payload delivery options | SOPHOS

Attackers operating the Gootkit loader compromised legitimate websites and used SEO poisoning to lure users searching for legal document templates into downloading malicious ZIP archives. The archives contained JavaScript that, once executed, launched obfuscated PowerShell and began a multi-stage infection chain designed to avoid writing the final payload to disk. Trend Micro reported that the updated intrusion flow used registry stuffing, scheduled-task persistence, and reflective in-memory loading to reconstruct and run a fileless Cobalt Strike beacon. The campaign differed from earlier Gootkit activity by shifting from freeware-themed lures to legal-document themes and by encrypting registry-stored content with a custom text-replacement algorithm instead of Base64; in the observed case, the beacon communicated with 89.238.185.13 before the attack was interrupted.

Feb 26
Dfir Report

SEO Poisoning to Domain Control: The Gootloader Saga Continues - The DFIR Report

Jan 26
Mandiant

Welcome to Goot Camp: Tracking the Evolution of GOOTLOADER Operations

Jan 9
Trend Micro Research

Gootkit Loader Actively Targets Australian Healthcare Industry | Trend Micro (US)

Jul 27
Trend Micro Research

Gootkit Loader’s Updated Tactics and Fileless Delivery of Cobalt Strike | Trend Micro (US)

Jul 20
Nviso

Analysis of a trojanized jQuery script: GootLoader unleashed - NVISO Labs

Jul 18
Esentire

eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID | eSentire

Dec 11
Trend Micro Research

Investigating the Gootkit Loader | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.