SunCrypt is a ransomware-as-a-service operation that emerged in late 2019 and became prominent in 2020 as part of the broader shift from single-extortion ransomware to multi-extortion campaigns. The group is known for combining file encryption with data theft and public leak-site pressure, and it was among the earlier ransomware operations observed adding distributed denial-of-service attacks to increase coercion against victims, making it an early practitioner of triple extortion. Reporting also describes SunCrypt as operating with affiliates and maintaining a relatively private or closed affiliate structure. SunCrypt used a dedicated leak site to publish stolen data from non-paying victims and to support negotiations. Victim pressure tactics included encryption, exfiltration, public exposure of stolen information, and in some cases DDoS attacks when negotiations stalled. The operation has been associated with attacks against high-value organizations, including healthcare entities, and later reporting indicates continued but limited activity while operators worked on adding capabilities to the malware. Technical reporting describes SunCrypt as a human-operated ransomware family distributed as a DLL payload and, in at least some cases, installed through obfuscated PowerShell. The malware encrypts local volumes and network shares, uses threaded encryption for speed, and includes logic to avoid encrypting certain system-critical items that could render hosts unusable before ransom collection. Newer variants added process termination, service stopping, machine-cleanup functionality, event-log wiping, and self-deletion after encryption. SunCrypt also maintained ransom-negotiation infrastructure and a leak blog rather than relying solely on automated payment workflows. Claims linked SunCrypt to the so-called Maze cartel, and SunCrypt operators asserted they were an independent member sharing communications and revenue with Maze. However, Maze publicly denied any affiliation. Available reporting supports at most a possible relationship involving shared infrastructure or loose cooperation, not a confirmed organizational merger. SunCrypt has also been referenced alongside other major ransomware brands in the affiliate-driven criminal ecosystem and is widely regarded as a financially motivated extortion actor rather than a state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11510 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11539 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-1579 (Global Protect)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-19781 (Citrix)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2020-2021 (Palo Alto)
1 more CVE tied to this actor tracked in Mallory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another ransomware operation with an affiliate program; also cited in an example involving a hospital attack by an affiliate.
Referenced as among the first ransomware operators to add DDoS to extortion, i.e., triple extortion.
Referenced as a ransomware gang that used Cryptomixer to launder ransom payments.
Used DDoS attacks during stalled negotiations to pressure victims into continuing ransom discussions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.