RansomEXX is a financially motivated ransomware operation active since at least 2018 and widely regarded as a rebrand of Defray777. The group is known for human-operated intrusions, double-extortion tactics, and targeting high-profile organizations across government, healthcare, manufacturing, transportation, technology, hospitality, and other enterprise sectors. Victims reported over time have included public-sector entities and large private organizations in multiple regions, and more recent reporting links the operation to activity affecting organizations in the United States, Europe, South America, the Middle East, and Asia. Microsoft tracks activity associated with RansomEXX as Storm-2460. This cluster has been tied to exploitation of high-severity and zero-day vulnerabilities for initial access or privilege escalation, including CVE-2025-29824 in the Windows Common Log File System and reporting that associates the group with exploitation of SAP NetWeaver Visual Composer vulnerability CVE-2025-31324 and Jenkins vulnerability CVE-2024-23897. Storm-2460 has also been associated with the modular backdoor PipeMagic, which has been used in staging and post-exploitation activity prior to ransomware deployment. RansomEXX tradecraft includes obtaining privileged access, moving laterally through enterprise environments, stealing data for extortion, and then deploying ransomware broadly across Windows and Linux systems. The group is notable for developing Linux encryptors to target critical servers, including virtualized infrastructure. Observed post-compromise behavior includes extensive use of living-off-the-land and dual-use tooling, such as MSBuild for code execution, CertUtil for payload retrieval or certificate-related abuse, ProcDump for credential theft from LSASS, bcdedit and wbadmin to inhibit recovery, and wevtutil or equivalent methods to disable or clear Windows event logging. Anti-forensic behavior and recovery inhibition are recurring elements of its operations. The actor has been linked to disabling Windows Security logging, deleting backups and shadow copies, and using modular malware to maintain access and facilitate follow-on actions. Reported campaigns indicate a preference for high-value targets and opportunistic exploitation of newly disclosed enterprise software vulnerabilities when patch adoption lags. Known aliases and associated tracking names include RansomEXX, Defray777, and Storm-2460. Some reporting and sanctions-related material have also connected individuals tied to broader Russian ransomware ecosystems with RansomEXX. Overall, RansomEXX is best characterized as a mature, financially motivated ransomware threat actor with a history of enterprise intrusion, data theft, cross-platform encryption capability, and aggressive use of vulnerability exploitation and anti-forensic techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The Common Log File System (CLFS) 0-day vulnerability CVE-2025–29824 was confirmed to have been exploited by attackers associated with PLAY and Storm-2460, and according to Symantec, the vulnerability may have already fallen into the hands of multiple attackers and been exploited before it was patched.
Ransomware groups and Chinese advanced persistent threat (APT) groups are targeting a critical vulnerability in SAP NetWeaver... The vulnerability, tracked as CVE-2025-31324, has a CVSS score of 10 and affects NetWeaver's Visual Composer development server. Threat actors can exploit the vulnerability using remote attacks to execute arbitrary code without authentication... SAP later confirmed it as an unrestricted file upload vulnerability... allowing attackers to upload malicious files directly to the system without authorization.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack and data breach against Go2Joy, with claims of releasing the complete database of the victim.
Mentioned as one of several threat actors that previously exploited SAP NetWeaver CVE-2025-31324 as a zero day.
Cybercrime group exploiting SAP NetWeaver vulnerability (CVE-2025-31324) to deploy PipeMagic trojan as part of intrusion activity.
Lumma Stealer is an infostealer malware that retrieves its command-and-control (C2) information from Telegram channels, using simple ciphers to obfuscate the C2 address and enable rapid infrastructure changes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.