Sarcoma is a ransomware family and ransomware-as-a-service operation first observed in October 2024 that rapidly became active in double-extortion campaigns worldwide. It has been associated with attacks against high-value organizations across multiple sectors, including manufacturing, supply chains, healthcare-related entities, government-linked organizations, and other small and medium-sized enterprises. Reported victim geography includes North America, Europe, and Asia, with notable activity affecting industrial and electronics manufacturing environments.
Sarcoma supports both Windows and Linux environments. The Windows variant is written in C++ and uses hybrid encryption, combining ChaCha20 for file encryption with RSA to protect per-file or per-session symmetric material. The Linux variant implements comparable hybrid encryption logic and has been observed using functionality intended to hinder recovery in virtualized environments by removing VMware snapshots. On Windows, Sarcoma has also been observed terminating database-related processes and services before encryption to maximize file access and operational disruption.
The malware includes anti-analysis and regional evasion behavior. A documented Windows sample checks for the Uzbek keyboard layout and, if present, deletes itself and exits. Sarcoma also performs passive and active network discovery, including local network enumeration and host reachability checks, then attempts lateral movement by copying itself to reachable remote systems over SMB or native Windows networking mechanisms. Remote execution has been observed via scheduled tasks, with authentication to target systems using valid credentials or tokens.
Sarcoma operators and affiliates have been described as using double extortion, combining data theft with encryption and subsequent leak-site pressure. The group has also been linked to supply-chain-focused targeting and abuse of legitimate remote management tooling for reconnaissance and lateral movement. Reported intrusion vectors include phishing, exploitation of older vulnerabilities, and supply-chain compromise. Public reporting has also described use of RDP during post-compromise movement. Overall, Sarcoma is a fast-evolving cross-platform ransomware threat notable for disruptive encryption, data exfiltration, lateral movement capability, recovery inhibition, and extortion-driven operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Radix ... said that Sarcoma ransomware affiliates compromised its systems on June 16."
2 distinct techniques documented for this family, organized by ATT&CK tactic.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sarcoma is a financially motivated ransomware group that combines data theft with system encryption for double-extortion. It targets organizations by stealing sensitive data before encrypting systems, then threatens public disclosure to pressure victims into paying. Sarcoma operates a Ransomware-as-a-Service (RaaS) model with a limited set of trusted partners, and its malware is capable of impacting Windows, Linux, and ESXi environments. The group is known for methodical, multi-stage intrusions, use of zero-day exploits, and advanced evasion and anti-forensics techniques.
Ransomware operation using double extortion, with noted impact on electronics manufacturing supply chains.
Ransomware group referenced as active by claimed victims (per Rapid7).
Ransomware group referenced as active by claimed victims (per Rapid7).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.