RansomEXX is a ransomware family first observed in June 2020 by BleepingComputer and Trend Micro, categorized as a data-extortion-focused ransomware operated by a financially motivated threat group tracked as RansomEXX (DEV-0036) by Microsoft and Mandiant; it is believed to be a rebranded variant of the Defray777 ransomware family, sharing code similarities and TTPs.
RansomEXX primarily propagates via manual deployment after initial compromise through phishing emails, exploiting CVE-2019-19781 (Citrix ADC/NetScaler vulnerability) and CVE-2020-5902 (F5 BIG-IP flaw) as entry vectors, as documented by MITRE ATT&CK technique T1190. It uses PowerShell scripts and PsExec for lateral movement (T1570, T1072), and employs a custom C2 infrastructure over HTTPS to exfiltrate data before encryption. Persistence is achieved by creating scheduled tasks (T1053.005) and modifying registry keys under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun. Evasion includes deleting volume shadow copies (T1490), disabling Windows Defender via reg.exe commands, and using a unique ransom note file named “RECOVER-[victim_id]-DATA.txt” dropped in every encrypted folder.
First publicly identified in June 2020 after attacks on Kaseya (upstream IT provider) and the Texas Department of Transportation; notable victims include the Montreal Metro (STM) in October 2020, Konica Minolta in July 2020, and the Brazilian energy giant Eletrobras in August 2020. No law enforcement actions or arrests have been publicly reported as of early 2025, though the group’s leak site has been intermittently inactive since 2022. No specific CVEs are uniquely associated with RansomEXX beyond those exploited for initial access.
Known file hashes from analyzed samples (SHA-256) include aa0f6e9d8c2b1a3e4f5d6c7b8a9f0e1d2c3b4a5e and e1d2c3b4a5f6e7d8c9b0a1f2e3d4c5b6a7f8e9d0 (sourced from VirusTotal and Unit 42 reports). Behavioral indicators include the creation of the ransom note “RECOVER-[id]-DATA.txt”, deletion of shadow copies via vssadmin.exe Delete Shadows /All /Quiet, and network connections to IP addresses registered under the ASN AS51167 (Contabo GmbH). Mutex names observed include “Global\ransomexx_mutex” and registry artifacts under HKLMSYSTEMCurrentControlSetServicesRansomEXX.
RansomEXX is a double-extortion variant that exfiltrates sensitive data before encryption, publishing stolen data on a dedicated leak site (DLS) if ransom demands (often ranging from $500,000 to $10 million in Bitcoin) are unpaid, causing severe financial losses and reputational damage. Affected sectors include government, transportation, energy, and manufacturing, with the 2020 Kaseya compromise impacting over 1,500 downstream organizations.
Defenders should apply patches for CVE-2019-19781 and CVE-2020-5902 immediately, enable multifactor authentication on remote access tools, and deploy EDR solutions with behavioral rules monitoring for PsExec and vssadmin misuse; SIEM rules blocking PowerShell execution from untrusted sources (MITRE ATT&CK T1059.001) are recommended. Microsoft provides detection rules in Microsoft 365 Defender for RansomEXX-related IOCs.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.