Researchers linked the Vatet loader, PyXie RAT, and Defray777 ransomware to the same financially motivated threat actor through shared development artifacts, including overlapping PDB paths, similar string-encryption routines, mutex logic, and ties to a Cobalt Mode downloader and Cobalt Strike delivery. The group has reportedly operated since 2018 and targeted organizations in healthcare, education, government, and technology, using a staged intrusion chain in which Vatet loads PyXie for reconnaissance and theft before Defray777—also known as RansomX—is deployed in memory to encrypt files.
An updated malware variant dubbed PyXie Lite shows the group refining that playbook with a smaller, repurposed implant focused on reconnaissance, credential theft, file collection, and exfiltration. Loaded by Vatet through a multi-stage in-memory chain, PyXie Lite uses a hardened custom Python interpreter with remapped opcodes and stores final-stage bytecode in an encrypted ZIP imported from memory; it collects system details, passwords, cookies, screenshots, PowerShell history, registry hives, and files matching espionage- and finance-related keywords, while also invoking tools such as Mimikatz and LaZagne. Staged data is compressed and encrypted with AES-CBC before exfiltration to configured servers, including compromised internal victim-network hosts listening on ports 31337, 900, and 8443.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported that the financially motivated threat group behind Vatet, PyXie, and Defray777 had been active since 2018. The group was described as targeting organizations in healthcare, education, government, and technology.
Unit 42 reported that the threat actors ported Defray777 from Windows to Linux. The report described Defray777 as the first targeted ransomware family in this context to have standalone executables for both operating systems.
Researchers exploited a search order hijacking weakness in the custom interpreter used by PyXie Lite to gain control of execution, disable anti-analysis behavior, generate bytecode, and recover remapped opcodes. This allowed them to dump the malware's configuration and further analyze its final-stage Python payloads.
Unit 42 documented an updated PyXie variant dubbed PyXie Lite that had been repurposed for reconnaissance, credential theft, file collection, and data exfiltration. The sample they analyzed was loaded by Vatet and used a multi-stage in-memory execution chain with a hardened custom Python interpreter.
Unit 42 published analysis concluding that Vatet, PyXie, and Defray777 were likely created and maintained by the same threat group. The attribution was based on shared development artifacts, overlapping PDB paths, similar string-encryption routines, and related mutex logic.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourcesecureworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.