Researchers detailed SugarLocker (also tracked as Sugar Ransomware and Encoded01) as a newly observed ransomware-as-a-service operation built in Delphi and marketed to affiliates through the RAMP forum by the user gustavedore. The operator advertised attacks via compromised network access and RDP, excluded most CIS countries from targeting, and offered tiered revenue-sharing terms. Analysis indicates the malware had been under development since at least early 2021 and included configurable RaaS features such as persistence, host identification, periodic C2 beaconing, automated Tor browser download for negotiations, and ransom notes including BackFiles_encoded01.txt, while encrypted files could carry the .encoded01 extension.
Technical reviews found code reuse between a custom crypter and the ransomware payload, including a modified RC4-like routine for unpacking and string decoding, suggesting a shared developer or tightly integrated build process. The malware uses the SCOP encryption algorithm from GPLib for file encryption, supports multiple file- and key-encryption algorithms, and includes a network mode that can reuse one encryption key across an entire victim environment, potentially enabling decryption with a single recovery tool. Researchers also noted ransom-note similarities to REvil and visual overlap with Cl0p infrastructure, but at the time of reporting had not confirmed real-world attacks or identified an active data leak site.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The operator using the handle “gustavedore” began ransomware-as-a-service recruitment on the RAMP forum in November 2021. The post advertised attacks via network access and RDP, excluded most CIS countries, and offered tiered revenue-sharing terms to affiliates.
An analyzed SugarLocker sample was created on 2021-09-04 18:00:27 UTC. S2W identified it as an x86 executable and provided its hashes in the report.
S2W assessed that the SugarLocker/Encoded01 ransomware had likely been under development since at least early 2021, based on functionality and later updates observed in samples.
S2W published a technical analysis of SugarLocker, also called Encoded01 ransomware, linking it to the operator “gustavedore.” The report documented its Delphi implementation, configurable encryption and key-encryption options, Tor-based negotiation portal, and the lack of confirmed real-world attacks or a leak site at that time.
Walmart Global Tech researchers published an analysis describing Sugar as a newly observed ransomware-as-a-service operation focused mainly on individual computers. The report detailed code reuse between a custom crypter and the ransomware, identified use of the SCOP algorithm from GPLib, and released indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.