Ranzy is a Windows ransomware family operated as a ransomware-as-a-service offering and associated with double-extortion activity. It emerged in late 2020 and is widely assessed as an evolution or rebranding of ThunderX, with some overlap also noted with Ako. The rebrand followed the appearance of free ThunderX decryption capabilities, and Ranzy introduced strengthened encryption as well as public leak-site extortion to increase pressure on victims.
Ranzy encrypts files on local and accessible network drives, appending family-specific extensions to affected data and dropping ransom notes in impacted directories. Reported variants use Salsa20 for file encryption together with an embedded RSA-2048 public key for key protection. The malware enumerates logical drives and network shares, excludes selected file types and system-related paths to preserve system operability, and uses multithreaded encryption to accelerate impact. It also invokes native Windows administration utilities to delete shadow copies, remove backups, and disable recovery options, and uses the Windows Restart Manager API to terminate processes that could interfere with encryption.
Ranzy is linked to data-theft extortion through a public leak site used to pressure non-paying victims. Victim organizations publicly associated with the operation have included entities in sectors such as electrical engineering, security and investigations, and government administration. Distribution has primarily been associated with phishing emails, with some reporting also indicating drive-by web delivery. Comparative malware analysis has identified code and implementation similarities between Ranzy, ThunderX, Ako, AVADDON, and MEDUSALOCKER, consistent with code sharing or reuse across ransomware ecosystems, although exact lineage and operator relationships are not fully resolved.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware operations known for affiliate programs and leak blogs.
Ransomware-as-a-Service family that encrypts files using an embedded RSA-2048 key and Salsa20, appends .ranzy or earlier .RNZ extensions, drops readme.txt ransom notes, deletes shadow copies and recovery options, can encrypt local and accessible network drives, and exfiltrates data for publication on the Ranzy Leak blog if victims do not pay.
Mentioned only in comparative statistics of ransomware leak sites.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.