Also known as: Hive0091
DefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for Windows. The group has been active since 2018 and has targeted various sectors, including healthcare and manufacturing. They have also developed other malware strains such as PyXie RAT, Vatet loader, and Defray ransomware.
Executive Summary
DefrayX, also known as Hive0091, is a cyber threat group primarily known for their RansomExx ransomware operations. They target both Linux and Windows operating systems, with a particular focus on sectors like healthcare and manufacturing since 2018. The group has demonstrated the ability to adapt their tactics, developing additional malware such as PyXie RAT and Vatet loader, poses a significant threat to critical infrastructure and organizations handling sensitive data.
Goals & Targeting
DefrayX's primary motivation appears to be financial gain through ransomware activities. By targeting sectors like healthcare and manufacturing, they likely focus on industries where data is both valuable and sensitive. Their choice of Linux as a primary target suggests an intent to exploit less defended or common attack vectors, potentially offering higher returns with lower competition compared to Windows. The group's development of multiple malware strains indicates an aim to diversify their toolkit to avoid detection and maintain operational persistence.
Enhanced Description
DefrayX is a cybercriminal group that emerged in 2018 and has since been involved in ransomware operations. The group primarily deploys RansomExx ransomware, which targets Linux systems but also includes Windows variants. This indicates a level of technical proficiency, as developing cross-platform malware requires different skill sets and knowledge about OS vulnerabilities. Beyond their ransomware activities, DefrayX has developed a range of other tools and malware strains, including PyXie RAT (remote access Trojan), Vatet loader, and Defray ransomware, showcasing their versatility as attackers. The group's targeting strategy focuses on industries where data breaches can yield high financial rewards or cause significant disruption—healthcare for sensitive patient records and manufacturing for supply chain data—highlighting a strategic approach to maximizing impact. Their continued operation since 2018 suggests a well-organized group with the capacity to evolve their tools and tactics over time.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DefrayX's campaigns demonstrate a focus on long-term, targeted operations against critical sectors. Their use of multiple malware types suggests an intent to adapt tactics over time, potentially evading detection by varied techniques. While specific campaign details remain limited, their sustained activity since 2018 indicates a professional and resourceful group. Expected targets include healthcare for patient data and manufacturing for supply chain information.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on DefrayX is sufficient to establish their primary activities and targets, including their ransomware operations and associated tools. However, specific details about their tactics, techniques, and procedures (TTPs) remain limited beyond general ransomware behavior. Additional intelligence gathering would enhance understanding of their operational strategies and any potential affiliations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics