MetaEncryptor is a ransomware operation associated with enterprise intrusions and extortion activity. It has been referenced in lineage discussions around the Sfile ransomware family and has also been observed in incidents where operators deployed the modular .NET remote access trojan CSHARP-STREAMER during post-compromise operations. Reported activity indicates a focus on corporate environments, including interest in IT service providers, with operators using remote access tooling and PowerShell-heavy tradecraft to support movement within segmented networks before or alongside ransomware deployment.
MetaEncryptor has been linked to intrusion chains in which a PowerShell loader decrypts and executes CSHARP-STREAMER in memory, using AMSI bypass techniques and obfuscated decryption logic. In observed cases, operators used the RAT’s relay capability to bridge protected network segments and relied extensively on PowerShell scripts for domain-user enumeration and other hands-on-keyboard actions rather than exclusively using the RAT’s full native module set. The associated tooling supports functions including keylogging, file transfer, relay, remote execution, and credential-oriented SMB operations, indicating a broader post-exploitation toolkit around the ransomware activity.
As a ransomware threat, MetaEncryptor is associated with data encryption and extortion against business victims. Reporting places it among lower-volume or minimally observed ransomware groups, but still relevant within the broader ecosystem of rebrands, splinters, and affiliate-driven operations. Its overlap with tooling also seen in REvil, LostTrust, and ALPHV intrusions suggests either shared service providers, malware-as-a-service relationships, or common operator ecosystems rather than a purely isolated malware lineage.
MetaEncryptor targets Windows enterprise environments and is associated with post-compromise behaviors such as in-memory execution, defense evasion through AMSI bypass, reconnaissance via scripted enumeration, and lateral movement or network pivoting through relay functionality. High-confidence reporting supports its characterization as ransomware used in targeted intrusions rather than indiscriminate commodity malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in the genealogy as a later family branch connected to the Sfile lineage.
Minimal-activity ransomware brand referenced as part of the long-tail of operators.
Ransomware deployed in the same incidents where CSHARP-STREAMER was observed; the article describes the actor behind Metaencryptor using the RAT and showing interest in IT service providers.
Ransomware family listed among active groups impacting industrial organizations in Q4 2023; also noted as first observed by Dragos in Q4 2023.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.