Rancoz is a ransomware threat actor observed in 2023 and referenced as part of the broader ransomware ecosystem targeting enterprise environments. Public reporting directly links Rancoz to ransomware activity and to host and network discovery behavior used to identify encryption targets. Specifically, Rancoz has been associated with enumerating drive types, including remote drives, to locate accessible data for encryption, indicating capability to discover and impact network-reachable storage in victim environments. Rancoz has also been noted among ransomware groups leveraging command and scripting tools, consistent with common operator tradecraft for execution, discovery, and post-compromise activity. Available high-confidence reporting in this context is limited, and there is insufficient corroborated information here to attribute the group to a specific country, define a stable victimology by geography or sector, or characterize its extortion model beyond ransomware operations. Known aliases include rancoz_ransomware_gang.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group observed in Q3 2023 but not observed in Q4 2023 (per Dragos tracking of industrial-targeting ransomware).
Ransomware using discovery (drive enumeration) to locate files across local/remote drives and network shares for encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.