LostTrust is a ransomware extortion operation that emerged publicly in 2023 and was observed among newer groups contributing to the diversification of the ransomware ecosystem. It has been associated with victim leak-site activity and was noted to have accumulated more than 50 listed victims during its early observed period, indicating a comparatively rapid operational tempo for a newly surfaced brand. Reporting also places LostTrust in proximity to the MetaEncryptor/Sfile lineage, suggesting branding or ecosystem overlap rather than a fully isolated operation.
Available information supports classifying LostTrust as a ransomware operation, but technical details on its payload, encryption workflow, persistence mechanisms, and post-compromise tradecraft remain limited in the supplied material. LostTrust has also been mentioned in connection with increased use of the .NET remote access trojan CSHARP-STREAMER across ransomware intrusions in 2023, though the exact nature of that relationship is not fully established. No high-confidence, directly supported delivery vector, platform specificity, or detailed capability set beyond ransomware-linked extortion activity is available from the provided facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a descendant in the family genealogy linked from the Sfile lineage.
Ransomware/extortion operation mentioned in temporal correlation with increased CSHARP-STREAMER usage.
Ransomware family listed among active groups impacting industrial organizations in Q4 2023; also noted as first observed by Dragos in Q4 2023.
A newly observed ransomware group; the content notes it had already listed more than 50 victim organizations on its leak site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.