Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DefrayX

Also known as: Hive0091

Description

DefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for Windows. The group has been active since 2018 and has targeted various sectors, including healthcare and manufacturing. They have also developed other malware strains such as PyXie RAT, Vatet loader, and Defray ransomware.

AI Analysis

· 1 week ago

Executive Summary

DefrayX, also known as Hive0091, is a cyber threat group primarily known for their RansomExx ransomware operations. They target both Linux and Windows operating systems, with a particular focus on sectors like healthcare and manufacturing since 2018. The group has demonstrated the ability to adapt their tactics, developing additional malware such as PyXie RAT and Vatet loader, poses a significant threat to critical infrastructure and organizations handling sensitive data.

Goals & Targeting

DefrayX's primary motivation appears to be financial gain through ransomware activities. By targeting sectors like healthcare and manufacturing, they likely focus on industries where data is both valuable and sensitive. Their choice of Linux as a primary target suggests an intent to exploit less defended or common attack vectors, potentially offering higher returns with lower competition compared to Windows. The group's development of multiple malware strains indicates an aim to diversify their toolkit to avoid detection and maintain operational persistence.

Enhanced Description

DefrayX is a cybercriminal group that emerged in 2018 and has since been involved in ransomware operations. The group primarily deploys RansomExx ransomware, which targets Linux systems but also includes Windows variants. This indicates a level of technical proficiency, as developing cross-platform malware requires different skill sets and knowledge about OS vulnerabilities. Beyond their ransomware activities, DefrayX has developed a range of other tools and malware strains, including PyXie RAT (remote access Trojan), Vatet loader, and Defray ransomware, showcasing their versatility as attackers. The group's targeting strategy focuses on industries where data breaches can yield high financial rewards or cause significant disruption—healthcare for sensitive patient records and manufacturing for supply chain data—highlighting a strategic approach to maximizing impact. Their continued operation since 2018 suggests a well-organized group with the capacity to evolve their tools and tactics over time.

Key Capabilities

  • Development of RansomExx ransomware
  • Linux-targeted attacks
  • Windows ransomware variants
  • PyXie RAT deployment
  • Vatet loader usage
  • Defray ransomware operations

MITRE ATT&CK Tactics

Ransomware
Initial Access
Execution
Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1566.002 (Phishing via Email)
T1045.004 (_masquerading_as_credential.harvesting_type_ dll)
T1059 (Malware Code Injection)
T1021 (Internal Spear Phishing)
T1574 (Exfiltration Over C2 Channel)
T1573 (Encryption)

Software / Tooling

RansomExx ransomware
PyXie RAT
Vatet loader
Defray ransomware

Campaigns & Victims

DefrayX's campaigns demonstrate a focus on long-term, targeted operations against critical sectors. Their use of multiple malware types suggests an intent to adapt tactics over time, potentially evading detection by varied techniques. While specific campaign details remain limited, their sustained activity since 2018 indicates a professional and resourceful group. Expected targets include healthcare for patient data and manufacturing for supply chain information.

IOC Patterns

  • Phishing emails with malicious links or attachments
  • Malicious scripts targeting Linux systems
  • C2 server communication over non-standard protocols
  • Ransomware encryption of files on Linux/Windows systems
  • Internal network exploration for data exfiltration

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts.
  • Monitor network traffic for signs of C2 communication channels.
  • Conduct regular vulnerability assessments, especially focusing on Linux systems.
  • Enforce strict access controls and encryption for sensitive data in healthcare and manufacturing sectors.
  • Educate employees about spear-phishing tactics through regular training.

Suggested Tags

Ransomware
Linux malware
Healthcare sector
Manufacturing sector
APT-like activity

Confidence Assessment

The available data on DefrayX is sufficient to establish their primary activities and targets, including their ransomware operations and associated tools. However, specific details about their tactics, techniques, and procedures (TTPs) remain limited beyond general ransomware behavior. Additional intelligence gathering would enhance understanding of their operational strategies and any potential affiliations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Linux malware
Healthcare sector
Manufacturing sector
APT-like activity

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.