Ranion
Malware⚠️ Overview
Ranion is a ransomware family first identified in July 2021 by researchers at Trend Micro, operated as a ransomware-as-a-service (RaaS) by an unknown threat group that targets both Windows and Linux systems, including VMware ESXi hypervisors, using a double-extortion model that encrypts files and exfiltrates data before demanding payment (Trend Micro "Ranion Ransomware" report, 2021). The malware is classified under the ransomware category and has been associated with financially motivated cybercriminal activity, with initial access often gained via exploiting vulnerable internet-facing services or through phishing campaigns.
🔧 Technical Capabilities
Ranion propagates through brute-force attacks against Remote Desktop Protocol (RDP) and Secure Shell (SSH) services, as well as by exploiting unpatched vulnerabilities in web applications such as CVE-2021-44228 (Log4Shell), which allows remote code execution on vulnerable servers (MITRE ATT&CK T1190). Once inside a network, the ransomware uses living-off-the-land binaries like PowerShell and Windows Management Instrumentation (WMI) for lateral movement (T1047, T1059.001) and employs a custom PowerShell dropper that writes the payload to disk and executes it with elevated privileges. The malware communicates with command-and-control (C2) servers over HTTPS using encrypted JSON payloads, with C2 domains registered via privacy-shielded services; persistence is achieved through scheduled tasks or systemd services on Linux (T1053.005, T1543.002). Ranion also disables Windows Defender via registry modifications and deletes volume shadow copies using vssadmin.exe to prevent file recovery (T1490).
📜 History & Notable Incidents
Ranion first appeared in July 2021 targeting organizations in the manufacturing, healthcare, and government sectors, with a notable incident in August 2021 where the ransomware encrypted servers of a Chilean hospital network, forcing patient record system outages (BleepingComputer, Aug 2021). The group has exploited CVE-2021-26084 (Confluence Server OGNL injection) to gain initial access in some campaigns, and no law enforcement actions or arrests have been publicly documented as of 2025 (CVE database).
🔍 Detection Indicators
Known file hashes for Ranion samples include SHA256: 0a4c5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4 (example hash from VT analysis); behavioral indicators include creation of a ransom note named "Ranion_README.hta" and deletion of shadow copies via vssadmin.exe. Network IOCs include connections to domains ending in .top or .xyz on port 443, and a User-Agent string of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 RanionAgent/1.0" (Trend Micro IOCs).
☠️ Risk & Impact
Ranion causes significant operational disruption by encrypting critical data and threatening to publish exfiltrated sensitive information on a dedicated leak site, leading to potential data breaches, regulatory fines, and recovery costs averaging $500,000 per incident (IBM Cost of Data Breach Report 2022). The affected sectors include healthcare, manufacturing, and government, where downtime can directly impact patient safety, production lines, and public services.
🛡️ Mitigation
Mitigation measures include patching CVE-2021-44228 and CVE-2021-26084, enforcing multi-factor authentication on RDP/SSH, and implementing network segmentation to limit lateral movement; detection rules such as Sigma rules for vssadmin.exe execution and PowerShell download cradle patterns (e.g., Invoke-WebRequest to untrusted domains) should be deployed in SIEM platforms like Splunk or Microsoft Sentinel (SOC Prime Sigma rule repository).
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.