Urausy is a Windows ransomware family from the early police-locker era that displayed coercive lock screens and was part of the broader evolution from Reveton-style lockers into later families such as Uremtoo and Nymaim-linked variants. It has been associated with country-tailored locker pages and with related operations including Lyposit and other successor or variant strains. Reporting also links Urausy-derived design elements to later locker campaigns, indicating code or operational lineage within the same criminal ecosystem.
Urausy was distributed through exploit-kit-driven traffic and botnet tasking. Observed delivery chains included malvertising redirects into exploit kit infrastructure, as well as secondary payload deployment onto already infected systems. These campaigns relied on the specialized ransomware distribution economy of the period, including traffers, traffic direction systems, redirectors, and exploit kits to route victims by geography and browser profile before malware delivery.
As ransomware, Urausy’s primary function was to deny normal system use and extort payment from victims. High-confidence reporting supports its use in mass consumer-focused campaigns rather than narrowly targeted intrusions. The malware targeted Windows systems and formed part of a cluster of financially motivated locker malware that imposed significant disruption and monetary loss on victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier ransomware family mentioned for comparison with CryptoLocker.
An earlier locker/ransomware family cited as the basis for Nymaim and visually/design-related to Bomba Locker/Lyposit.
Ransomware mentioned as being pushed via existing botnet infections and also delivered through exploit-kit-driven malvertising.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.