Lorenz is a human-operated ransomware family and extortion operation associated with targeted intrusions against enterprise environments worldwide. It has been linked by multiple researchers to earlier ThunderCrypt and SZ40 code lineage, although operator continuity has not been conclusively established. Lorenz has been used in customized attacks with ransom demands commonly in the hundreds of thousands of dollars and has employed double-extortion tactics by stealing victim data before encryption and threatening public release through a dedicated leak site.
Lorenz intrusions have involved hands-on-keyboard post-compromise activity, including credential harvesting, privilege escalation to local and domain administrator access, lateral movement across Windows networks, and pre-encryption data exfiltration. Observed operator tradecraft includes use of reverse shells and tunneling utilities for pivoting, living-off-the-land commands for discovery, credential dumping from LSASS, remote tasking, and log clearing for defense evasion. In at least one investigated intrusion, the actor gained initial access by exploiting CVE-2022-29499 in a Mitel MiVoice Connect appliance, established persistence with a webshell, tunneled into the internal network, exfiltrated data over SFTP, and then used Microsoft BitLocker at scale for encryption while also deploying Lorenz ransomware to a limited number of ESXi hosts.
The malware encrypts files using symmetric encryption protected by an embedded asymmetric key and has been observed dropping HTML ransom notes and directing victims to dedicated negotiation portals. Samples have been customized per victim organization. Lorenz operators have also advertised stolen data and, in some cases, access to victim networks as part of their extortion model.
A notable implementation flaw in Lorenz’s encryption routine permanently truncates the last 48 bytes of files whose size is an exact multiple of 48 bytes, rendering those bytes unrecoverable even with an attacker-supplied decryptor. Because of this flaw and subsequent reverse engineering, partial recovery has been possible for some victims and certain file types through a public decryptor. Lorenz has primarily been associated with enterprise-focused big-game hunting operations rather than indiscriminate mass campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...deployed Lorenz ransomware... exploiting a novel remote code execution (RCE) flaw on Mitel's MiVoice Connect VOIP appliance (CVE-2022-29499).
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family listed among active groups impacting industrial organizations in Q4 2023.
Ransomware family used by the Lorenz group for double-extortion: initial access via Mitel MiVoice Connect RCE (CVE-2022-29499), persistence via a webshell, credential dumping (LSASS), data exfiltration (FileZilla/SFTP), and encryption primarily via BitLocker plus Lorenz ransomware on some ESXi hosts.
Ransomware used in enterprise-targeted attacks that encrypts victim files and operates a leak site to publish stolen data from victims who refuse to pay. The report notes an encryption bug that allows recovery of some non-corrupted files in certain cases.
Enterprise-targeting ransomware operation that customizes payloads per victim, steals unencrypted files for double extortion, offers stolen data and even internal network access for sale, encrypts files with AES and an embedded RSA key, appends the .Lorenz.sz40 extension, and drops HELP_SECURITY_EVENT.html ransom notes linking to Tor payment and leak sites.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.