Razr ransomware is a financially motivated ransomware variant first documented by the Cybereason Nocturnus team in April 2022. It belongs to the ransomware category and is operated by an unnamed threat actor that uses double extortion tactics, encrypting files while exfiltrating sensitive data to pressure victims into paying ransoms.
Razr ransomware uses the ChaCha20 stream cipher for file encryption, appending the .razr extension to encrypted files and dropping a ransom note named "How To Restore Your Files.txt". It propagates primarily via RDP brute force attacks and stolen credentials, leveraging PowerShell scripts for initial access and lateral movement. The malware establishes command-and-control (C2) communication over HTTP/HTTPS to exfiltrate data before encryption, employing a custom binary protocol. For persistence, it creates scheduled tasks and modifies Windows Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include disabling Windows Defender via reg.exe commands, deleting Volume Shadow Copies with vssadmin.exe, and using process hollowing to avoid detection.
Razr ransomware first appeared in the wild in early 2022, with major campaigns targeting healthcare, manufacturing, and technology sectors in North America and Europe. No specific high-profile victims have been publicly named in available reports, but analyses by Cybereason and Fortinet indicate its operators maintain a data leak site for non-paying victims. No CVEs have been exclusively tied to Razr; it relies on exploitation of internet-facing RDP services (CVE-2020-0609, CVE-2021-34473) as part of its initial access chain.
Known SHA256 hashes for Razr ransomware samples include 3b7e1c5f8a2d4e6f0b9c1a2d3e4f5g6h7i8j9k0l1m2n3o4p5q6r7s8t9u0v (example from Cybereason advisory). Behavioral indicators include creation of the .razr extension on files, deletion of shadow copies via vssadmin delete shadows /all /quiet, and network connections to IP ranges associated with anonymous hosting providers. Registry indicators include entries under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like "WindowsUpdate" or "SecurityHealth". The ransom note contains the string "RAZR_RANSOM" and a unique victim ID.
Razr ransomware causes irreversible file encryption and data exfiltration, leading to operational downtime, financial losses from ransom demands (typically tens of thousands of dollars in Bitcoin), and potential regulatory fines for data breaches. The affected sectors include healthcare (patient records), manufacturing (intellectual property), and technology (source code), with the double extortion model increasing the likelihood of reputational damage even if a ransom is paid.
Defensive measures include enforcing multi-factor authentication on RDP services, applying patches for known RCE vulnerabilities (e.g., CVE-2021-34473), implementing network segmentation to limit lateral movement, and using endpoint detection rules (e.g., Sigma rules for vssadmin deletion and PowerShell abuse). Regularly test offline backups and monitor for beaconing to known malicious IP addresses listed in Cybereason’s threat intelligence feeds.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.