Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ransomexx

Description

RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777. Known victims: 85 5 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

RansomExx is a medium-sophistication ransomware group targeting organizations for financial gain through data encryption and double extortion tactics. Linked to the Defray777 ransomware family, RansomExx has been active since May 2020 and primarily targets sectors like healthcare, education, and critical infrastructure. Their operations involve phishing campaigns, initial access via email attachments, and lateral movement within networks.

Goals & Targeting

RansomExx's primary objective is financial gain, achieved through ransom payouts and the sale of stolen data. They target sectors with high potential for valuable data, such as healthcare, education, and critical infrastructure. Their victims include small to large businesses, suggesting a broad targeting strategy aimed at maximizing their attack surface.

Enhanced Description

RansomExx is a ransomware group that emerged in mid-2020 and has been associated with the Defray777 ransomware family. The group primarily operates through double extortion tactics, where they encrypt victims' data and demand a ransom for its decryption. RansomExx has targeted numerous organizations globally, including businesses, educational institutions, and government entities. They are known to use phishing emails as their initial infection vector, often leveraging malicious links or attachments to gain access to target networks. The group has also been observed using custom tools and scripts to deploy their ransomware. Their operations are characterized by a focus on financial gain through ransoms and the sale of victim data.

Key Capabilities

  • Double extortion tactics
  • Email-based phishing campaigns
  • Custom ransomware deployment
  • Network lateral movement

MITRE ATT&CK Tactics

Defense Evasion
Execution Protection
Data Collection
Credential Access
Discovery
Response Evading

ATT&CK Techniques

T1543
T1204
T1070
T1003
T1091
T1486

Software / Tooling

Custom ransomware (similar to Defray777)
File indexer tool for double extortion
Cobalt Strike (likely used in some campaigns)

Campaigns & Victims

RansomExx has been involved in notable campaigns such as the SOGO Auction, GoTip, and Go2Joy attacks. Their operations demonstrate a preference for Target industries with high-value data and a willingness to evolve their tactics over time. The group's operational tempo is steady but not frequently observed due to limited active reporting beyond known campaigns.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Encrypted files with specific file extensions (e.g., .RansomExx)
  • Lateral movement via network shares and remote desktop protocol
  • Use of custom tools for data exfiltration

Recommended Actions

  • Implement endpoint detection and response (EDR) solutions to monitor for suspicious file activity。
  • Conduct regular backups and ensure they are isolated from the network to prevent ransomware encryption.
  • Educate users on phishing email recognition and social engineering tactics.
  • Enforce multi-factor authentication (MFA) for all critical systems, especially email and RDP access。
  • Monitor network traffic for signs of unusual lateral movement or exfiltration attempts.

Suggested Tags

Ransomware
Double extortion
Financial gain
Criminal activity
Network infiltration

Confidence Assessment

Confidence in the data is medium due to known campaigns and TTPs, although specific technical details such as exact tools or attack vectors remain unclear. Limited active reporting on this group beyond high-profile attacks contributes to gaps in understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

3

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Double extortion
Financial gain
Criminal activity
Network infiltration

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 14, 2020
Last Seen
Jun 20, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.