SunCrypt is a ransomware-as-a-service operation that emerged in late 2019 and became prominent in 2020 as part of the broader shift toward multi-extortion ransomware. The group is known for combining file encryption with data theft and public leak-site pressure, and it was identified as an early adopter of triple extortion by adding distributed denial-of-service attacks against victims during stalled negotiations. SunCrypt maintained a dedicated leak blog to publish stolen data from non-paying victims and operated through affiliates in what has been described as a relatively small, private RaaS model. SunCrypt targeted high-value organizations and has been linked to attacks affecting healthcare and large enterprises, including victims in the United States and Switzerland. Reported victimology includes a New Jersey teaching hospital and a major Swiss retail organization. The operation publicly claimed theft of large volumes of sensitive data in some incidents and used leak-site publication as a coercive mechanism. Technically, SunCrypt has been observed using a PowerShell-based installation chain and DLL payloads. Its ransomware encrypts local volumes and network shares, appends a victim-specific marker to encrypted files, and drops HTML ransom notes directing victims to a negotiation portal. Later variants added process termination, service stopping, machine-cleanup functionality, event-log wiping, and self-deletion, while retaining threaded encryption optimizations and allowlists intended to avoid rendering systems unbootable. SunCrypt’s extortion workflow included manual negotiation rather than fully automated payment handling. The operation has also been associated with DDoS-backed extortion pressure and with laundering ransom proceeds through cryptocurrency mixing services. SunCrypt publicly claimed at one point to be affiliated with the so-called Maze Cartel, but that relationship was disputed and remains uncorroborated as a formal organizational tie. SunCrypt is widely regarded as an early multi-extortion ransomware gang rather than a state-sponsored actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another ransomware operation with an affiliate program; also cited in an example involving a hospital attack by an affiliate.
Referenced as among the first ransomware operators to add DDoS to extortion, i.e., triple extortion.
Referenced as a ransomware gang that used Cryptomixer to launder ransom payments.
Used DDoS attacks during stalled negotiations to pressure victims into continuing ransom discussions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.