Matrix ransomware has targeted small- to medium-sized organizations in multiple countries since its public emergence in 2016, with its delivery methods shifting over time from spam emails, malicious Windows shortcut files, and the RIG exploit kit to the brute forcing of weak Remote Desktop Protocol (RDP) credentials. The campaign reflects a broader move toward targeted ransomware intrusions that rely on exposed remote access services rather than mass distribution alone.
Once launched, Matrix encrypts local files and network shares, deletes volume shadow copies, disables recovery options, and demands payment in Bitcoin. Operators use a variable ransom model in which victims are told to make contact and provide sample files for decryption so the attackers can assess payment demands; known variants use multiple file extensions, including the Fox strain that appends .FOX to encrypted files.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
By 2018, Matrix's primary attack vector had shifted from earlier methods such as spam, malicious Windows shortcuts, and the RIG exploit kit to brute forcing weak Remote Desktop Protocol credentials. The report says this mirrored trends seen in other targeted ransomware operations.
Matrix was first publicly identified as a ransomware family in December 2016. The family primarily targeted small- to medium-sized organizations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.