Lorenz is a human-operated ransomware and extortion group associated with customized intrusions against enterprise organizations worldwide. The operation emerged in 2021 and has been linked by researchers to code overlap or lineage with the older ThunderCrypt and SZ40 ransomware families, although operator continuity has not been established with high confidence. Lorenz has used a double-extortion model, stealing data before encryption and pressuring victims through a dedicated leak site. The group has also advertised stolen data and, in some cases, offered access to victim networks for sale. Lorenz has conducted targeted intrusions rather than indiscriminate mass campaigns. Reported tradecraft includes exploitation of internet-exposed edge infrastructure for initial access, notably CVE-2022-29499 affecting Mitel MiVoice Connect appliances, followed by reverse-shell access, tunneling with Chisel, credential harvesting, and lateral movement. Observed post-compromise activity includes LSASS dumping, use of CrackMapExec and lsassy, account creation for persistence, RDP-based movement, network and Active Directory discovery, and extensive living-off-the-land activity. In one documented intrusion, the group adapted after defensive interference, later regaining access through compromised VPN credentials associated with a third-party vendor account. For defense evasion and post-exploitation, Lorenz has abused legitimate tools as well as native administrative mechanisms. Documented behavior includes use of Magnet RAM Capture to dump physical memory and bypass endpoint protections through its signed kernel driver, clearing Windows event logs, and staging activity through scheduled tasks and remote administration workflows. Data theft has been observed via FileZilla over SSH/SFTP. Lorenz has used multiple impact mechanisms. In Windows environments, the group has deployed BitLocker at scale through PowerShell and scheduled tasks; in some cases it also deployed Lorenz ransomware to ESXi hosts. The ransomware operation is known for high-value ransom demands in the hundreds of thousands of dollars. A flaw in the Lorenz encryption routine enabled development of a partial decryptor for some file types, though recovery is not universal and some encrypted files remain irreparably damaged. Known aliases and related names include Lorenz and references connecting the malware lineage to ThunderCrypt and SZ40.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group that previously claimed a breach of Cencora (then AmerisourceBergen) in Feb 2023, alleging theft of data related to the Animal Health division. No group has claimed responsibility for the Feb 2024 Cencora incident described.
Ransomware group reported as an observed incident driver against industrial organizations in Q4 2023.
Conducting ransomware intrusions by exploiting Mitel MiVoice appliances, regaining access with compromised VPN credentials, bypassing EDR using Magnet RAM Capture, dumping credentials, exfiltrating data with FileZilla, and attempting encryption via BitLocker.
Ransomware and double-extortion operations: initial access via Mitel MiVoice Connect RCE (CVE-2022-29499), persistence via webshell, pivoting with Chisel SOCKS tunneling, credential dumping (LSASS) using CrackMapExec/lsassy, lateral movement via RDP, data exfiltration via FileZilla SFTP, and encryption primarily using BitLocker (plus Lorenz ransomware on some ESXi hosts), followed by log clearing for defense evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.