SunnyDay is a ransomware threat actor or campaign name associated with a custom-branded Windows locker built from the same codebase used for Vice Society and Chily. Analysis of the malware lineage indicates SunnyDay is distinct from Vice Society despite substantial code overlap, with differences concentrated in campaign-specific configuration such as ransom messaging, file-extension branding, and embedded keying material. This suggests SunnyDay likely obtained ransomware tooling from a shared specialist developer or builder service rather than developing a wholly unique locker. The SunnyDay payload is part of a broader ransomware ecosystem in which external developers supply customized encryptors to multiple operators. The underlying locker family uses a hybrid cryptographic design combining NTRUEncrypt with ChaCha20-Poly1305 and supports multithreaded encryption of local drives, remote drives, and network shares. Related variants demonstrate capabilities for rapid file encryption, recursive file discovery, and partial encryption strategies for larger files to improve speed and operational impact. High-confidence reporting ties SunnyDay to ransomware operations, but the available information does not directly establish its geographic origin, victim-country focus, or sector specialization. The evidence supports classification as a financially motivated ransomware actor using encryption for extortion, while broader intrusion behaviors beyond the locker’s encryption and file-enumeration capabilities are not directly attributed to SunnyDay at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate threat group identified through use of an older custom-branded ransomware payload built from the same codebase as Vice Society's PolyVice payload.
Mentioned only in passing as a similar related variant.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.