Ranzy Locker is a Windows ransomware family that emerged in late 2020 as a rebranded successor to ThunderX and has also been linked by lineage and shared infrastructure to Ako. It was used by financially motivated operators in intrusions against U.S. organizations across sectors including construction, academia, information technology, transportation, manufacturing, and government-related environments. By mid-2021 it had been associated with compromises of more than 30 U.S. businesses.
Ranzy Locker is operated as a double-extortion ransomware, combining file encryption with theft of sensitive data and threats to publish stolen information if victims refuse to pay. Reported pre-encryption collection objectives included customer information, personally identifiable information, and financial records. The malware encrypts files on compromised Windows systems, including servers, virtual machines, and attached network shares, and leaves ransom notes throughout affected directories. Operators also maintained a leak site and negotiation portal to pressure victims and facilitate payment discussions.
Observed initial access methods included brute-force attacks against Remote Desktop Protocol credentials, use of valid accounts over RDP, exploitation of known Microsoft Exchange Server vulnerabilities, and phishing. Post-compromise behavior included attempts at lateral movement across the victim network, discovery of mounted drives and SMB shares, enumeration of processes, and network-oriented discovery activity. Ranzy Locker also attempted to establish additional accounts in some environments.
The malware includes anti-recovery and defense-evasion behavior typical of mature ransomware operations. It deletes shadow copies and backups, disables Windows recovery features, and can terminate processes or services that keep files open in order to maximize encryption coverage. Technical reporting has also described use of Windows APIs for system interaction and anti-debugging checks. Public reporting further characterizes Ranzy Locker as an improved continuation of ThunderX after flaws in earlier ThunderX samples enabled free decryption for some victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware gang leverages valid accounts with Remote Desktop Protocol (RDP) to access target systems.
Ranzy reads the host file ( C:\Windows\System32\drivers\etc\hosts ) to discover the hostname to IP address mappings of remote systems.
The ransomware queries the volume information to determine the disks in the system.
The Ranzy Locker ransomware discovers critical files to exfiltrate, such as customer data, personally identifiable information (PII) files, and financial records. It uses GetLogicalDrives API call to enumerate all mounted drives.
The Ranzy Locker ransomware scans all drive letters to infect USB drives.
The actors attempted to locate important files to exfiltrate, such as customer information, PII related files, and financial records.
Some of these strings are commands used to delete any backups on the system.
Этот крипто-вымогатель шифрует данные пользователей с помощью Salsa20... К зашифрованным файлам добавляется случайное расширение... В обновленном варианте стало использоваться расширение: .tx_locked... Позже, вариант Ranzy Locker получил расширения .RNZ и .ranzy
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ranzy Locker is a ransomware family that disables Windows recovery features and deletes system state backups to prevent victims from restoring their systems after an attack.
Double-extortion ransomware operated under a ransomware-as-a-service model. It exfiltrates sensitive data before encrypting files, uses Salsa20 to encrypt files and RSA-2048 to encrypt Salsa20 keys, spreads via phishing, valid RDP accounts, and exploitation of Microsoft Exchange Server vulnerabilities, and inhibits recovery by deleting backups and shadow copies.
Ranzy Locker is a ransomware variant that encrypts files and demands ransom, targeting a range of organizations.
Ransomware that encrypts files, appends the .ranzy extension, deletes Shadow Volume Copies, uses Windows Restart Manager to terminate processes/services locking files, drops a 'readme.txt' ransom note, provides a Tor-based negotiation portal, and supports double-extortion by stealing data and leaking it on the 'Ranzy Leak' site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.