SunCrypt is a ransomware family and ransomware-as-a-service operation active from approximately October 2019 and prominent in 2020. Early variants were written in Go and targeted Windows systems; later variants were implemented in C/C++. SunCrypt encrypts files on local volumes and network shares, while maintaining exclusions intended to preserve operating-system functionality. It leaves ransom instructions directing victims to a Tor-based negotiation service and has used a dedicated leak site to threaten publication of stolen victim data.
SunCrypt adopted double extortion by combining encryption with data theft and public-leak threats, and was an early user of triple extortion, adding distributed-denial-of-service attacks against victims when negotiations stalled. The operation has been associated with a small, closed affiliate program. Technical analysis found substantial code overlap between an early SunCrypt variant and QNAPCrypt/eCh0raix, although the operations were assessed as likely run by separate actors.
Later SunCrypt variants added termination of processes and services that may lock files, host-cleanup behavior, event-log clearing, and self-deletion following encryption. SunCrypt has affected organizations including healthcare entities, and remained active at a limited visible level after its initial 2020 prominence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SunCrypt ransomware operation has leaked data allegedly stolen from UHNJ in a September ransomware attack. SunCrypt is a ransomware operation that began its activities in October 2019.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The SunCrypt Ransomware sample is installed via a heavily obfuscated PowerShell script, shown below.
The cleaning feature is activated at the end of the encryption routine, using two API calls to wipe all logs.
Of the 240 GB of data allegedly stolen from University Hospital New Jersey, the attackers have leaked a 1.7 GB archive containing over 48,000 documents.
SunCrypt was one of the early pioneers of triple extortion, including file encryption, threat to publish stolen data, and DDoS (distributed denial of service) attacks on non-paying victims. | SunCrypt continues to encrypt both local volumes and network shares
The new capabilities of the 2022 SunCrypt variant include process termination, stopping services, and wiping the machine clean for ransomware execution.
Another approach may involve “Ransom DDoS attacks” (RDDoS) where the RDDoS attackers use the threat of taking down the organization’s network or other such aggressive approaches.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a ransomware operation with an affiliate program; also cited in an example where an affiliate attacked hospitals.
SunCrypt is a ransomware-as-a-service family linked by code reuse to QNAPCrypt. It encrypts files, steals data, presents a ransom note with victim chat capability, avoids some CIS-region victims, uses Tor-hidden-service C2 infrastructure, and in later campaigns targeted organizations including healthcare providers.
Ransomware family cited as an early adopter of triple extortion by adding DDoS attacks to encryption and data-leak threats.
Ransomware family whose affiliate used DDoS pressure tactics during stalled ransom negotiations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.