ThunderX is a Windows ransomware family that emerged in 2020 and was later rebranded as Ranzy Locker. It is widely assessed as part of the broader MedusaLocker/Ako lineage, with substantial overlap in code structure, behavior, and operator tradecraft. ThunderX encrypts victim data using Salsa20 with asymmetric key protection, appends variant-specific extensions to encrypted files, and drops ransom notes instructing victims to pay for decryption. Later operations associated with its Ranzy rebrand added more mature extortion workflows, including dedicated negotiation portals and leak-site pressure.
ThunderX targets Windows systems and can encrypt files on local drives, servers, virtual machines, and accessible network shares. Its behavior includes enumerating drives and shared resources, multithreaded encryption, and attempts to maximize file access by terminating processes that may lock files. It also inhibits recovery by deleting shadow copies and backups and disabling recovery-related features through native Windows administration utilities. Related Ranzy activity additionally involved data theft prior to encryption and threats to publish stolen information, indicating evolution toward double-extortion ransomware operations.
Observed intrusion vectors associated with ThunderX and its Ranzy successor include brute-force attacks against exposed Remote Desktop Protocol services, phishing, and exploitation of vulnerable Microsoft Exchange Server deployments. Reporting also links the family more broadly to common ransomware distribution channels such as malicious attachments, deceptive downloads, exploit-driven delivery, fake updates, and trojanized installers, though the highest-confidence delivery mechanisms directly tied to later Ranzy intrusions are RDP brute force, phishing, and Exchange exploitation. Victims have included organizations in sectors such as construction, academia, information technology, transportation, manufacturing, and government-related environments.
ThunderX is notable for its historical transition into Ranzy Locker after free decryption options for ThunderX became available. The rebrand was accompanied by changes in branding, ransom-note workflow, and extortion infrastructure, while retaining core technical characteristics and lineage links to Ako. Security professionals commonly encounter ThunderX in discussions of ransomware family evolution, code reuse across ransomware-as-a-service ecosystems, and the progression from straightforward file encryption to data-theft-enabled extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Этот крипто-вымогатель шифрует данные пользователей с помощью Salsa20... К зашифрованным файлам добавляется случайное расширение... В обновленном варианте стало использоваться расширение: .tx_locked... Позже, вариант Ranzy Locker получил расширения .RNZ и .ranzy
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the predecessor/rebranded basis for Ranzy Locker.
Predecessor ransomware family to Ranzy; shares code, multithreading, ransom-note structure, and other implementation elements. Ranzy appears to be a rebrand/evolution intended to improve encryption and evade free decryptors.
Referenced as another ransomware family known to use the Windows Restart Manager feature.
Named as a descendant/related family in the MedusaLocker genealogy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.