RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777. Known victims: 85 5 ransom note(s) on file
Objectives
Executive Summary
RansomExx is a medium-sophistication ransomware group targeting organizations for financial gain through data encryption and double extortion tactics. Linked to the Defray777 ransomware family, RansomExx has been active since May 2020 and primarily targets sectors like healthcare, education, and critical infrastructure. Their operations involve phishing campaigns, initial access via email attachments, and lateral movement within networks.
Goals & Targeting
RansomExx's primary objective is financial gain, achieved through ransom payouts and the sale of stolen data. They target sectors with high potential for valuable data, such as healthcare, education, and critical infrastructure. Their victims include small to large businesses, suggesting a broad targeting strategy aimed at maximizing their attack surface.
Enhanced Description
RansomExx is a ransomware group that emerged in mid-2020 and has been associated with the Defray777 ransomware family. The group primarily operates through double extortion tactics, where they encrypt victims' data and demand a ransom for its decryption. RansomExx has targeted numerous organizations globally, including businesses, educational institutions, and government entities. They are known to use phishing emails as their initial infection vector, often leveraging malicious links or attachments to gain access to target networks. The group has also been observed using custom tools and scripts to deploy their ransomware. Their operations are characterized by a focus on financial gain through ransoms and the sale of victim data.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RansomExx has been involved in notable campaigns such as the SOGO Auction, GoTip, and Go2Joy attacks. Their operations demonstrate a preference for Target industries with high-value data and a willingness to evolve their tactics over time. The group's operational tempo is steady but not frequently observed due to limited active reporting beyond known campaigns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is medium due to known campaigns and TTPs, although specific technical details such as exact tools or attack vectors remain unclear. Limited active reporting on this group beyond high-profile attacks contributes to gaps in understanding.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
3
Campaigns
0
IOCs
0
Observed Data
0
Tactics