Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal.
Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
On 2021-10-25, the FBI, coordinated with DHS/CISA, issued a FLASH detailing Ranzy Locker indicators of compromise, intrusion methods, victim targeting, and detection artifacts including recurring "felix" accounts and a YARA rule. The notice also said the FBI had first identified Ranzy targeting U.S. victims in late 2020 and reiterated that more than 30 U.S. businesses had been compromised as of July 2021.
An FBI flash report cited in the reporting stated that Ranzy Locker had compromised more than 30 businesses in the United States as of July 2021. Victims were reported in sectors including manufacturing, government, transportation, and IT.
By October 2020, the rebranded Ranzy Locker operation had launched a Tor-based leak site called Ranzy Leak to publish stolen data from non-paying victims. The site had already listed one victim, marking Ranzy's active use of double-extortion pressure infrastructure.
Ranzy emerged in September/October as a ransomware-as-a-service operation and was described as an improved rebrand of ThunderX, with some continuity to Ako. The new variant added stronger encryption and adopted double-extortion tactics including data theft and leak-site pressure.
A free decryption tool for ThunderX was posted to the NoMoreRansom project in September of the referenced year. Reporting says this helped trigger the operators' rebrand to Ranzy.
ThunderX ransomware emerged around August 2020. Subsequent analyses identified Ranzy as a rebranded evolution of ThunderX.
Ranzy Locker was reported as being responsible for dozens of high-profile breaches since late 2020. The activity marked the start of a broader victimization campaign across multiple sectors.
Early Ako ransomware samples were observed around January 2020. Later Ranzy reporting described Ranzy as reusing infrastructure associated with Ako and as a partial successor to it.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
picussecurity.com
Open sourcelabs.sentinelone.com
Open sourcebleepingcomputer.com
Open sourceid-ransomware.blogspot.com
Open sourcecrowdstrike.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.