The Lorenz ransomware operation emerged as an enterprise-focused threat using double extortion: attackers stole unencrypted data before encrypting systems, then pressured victims by publishing stolen files on a leak site and, in some cases, offering both the data and internal network access for sale. Reported ransom demands ranged from $500,000 to $700,000, with victims directed to a dedicated Tor payment portal featuring Bitcoin payment instructions and live chat. Researchers said the malware appears linked to earlier ThunderCrypt and SZ40 ransomware, though it remained unclear whether the same operators were involved or whether code had been reused.
Analysis of the malware showed it uses AES encryption with an embedded RSA key, appends the .Lorenz.sz40 extension to encrypted files, and drops a ransom note named HELP_SECURITY_EVENT.html. A later breakthrough by Tesorion led to a free decryptor being added to the NoMoreRansom project, allowing recovery of some files without paying. The researchers found a flaw in Lorenz’s encryption routine that irreversibly destroys the last 48 bytes of files whose size is a multiple of 48 bytes, meaning some data remains corrupted even if decrypted, while other file types such as Microsoft Office documents, PDFs, and some images and videos can be recovered in certain cases.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Arctic Wolf Labs reported additional Lorenz intrusions, including at least one late-2022 case where the attackers exploited CVE-2022-29499 on exposed Mitel MiVoice appliances, later regained access with compromised VPN credentials, and adapted their tactics after earlier activity was blocked. The report said Lorenz used Magnet RAM Capture on a Mitel Digital Voicemail server to dump physical memory and bypass EDR, which Arctic Wolf described as the first publicly documented Lorenz case using that tool.
Researchers said the Lorenz ransomware gang began operating in the month before the May 2021 report, conducting customized intrusions against organizations worldwide. The operation used double extortion, stealing data before encryption and publishing victims on a leak site.
By the time of The Record's report, the Lorenz gang's dark web leak site listed 13 victims. The article said the ransomware had been used exclusively against enterprise targets in its most recent form.
After Tesorion released its tool, the Lorenz decryptor was added to the NoMoreRansom project. The tool was described as non-universal, working only for some file types and cases.
Tesorion researcher Gijs Rijnders reported that Lorenz contains a bug that permanently destroys the last 48 bytes of files whose size is a multiple of 48 bytes. Because of this flaw, some files are unrecoverable even with a decryptor from the attackers, while some non-corrupted files can still be decrypted.
Tesorion released a free decryptor for some Lorenz ransomware victims and announced it in a blog post. The tool was intended to help recover certain encrypted files without paying the ransom.
At the time of BleepingComputer's reporting, Lorenz's leak site listed 12 victims, with data already released for 10 of them. The article also described the gang's practice of selling stolen data and even access to victims' internal networks.
Security researchers assessed that the Lorenz encryptor appears to be the same as or evolved from the earlier ThunderCrypt and SZ40 ransomware families. The reporting noted uncertainty over whether this reflected the same operators or reuse of source code.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
arcticwolf.com
Open sourcenews.sophos.com
Open sourcetrendmicro.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.