Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family.
The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
IBM Security X-Force reported a new Linux variant of RansomEXX, dubbed RansomExx2, that was rewritten in Rust while retaining similar encryption behavior to earlier versions. The report also attributed RansomEXX operations to the DefrayX group, also tracked as Hive0091.
Profero found that the Linux RansomEXX encryptor did not lock files during encryption, which could corrupt files and cause the attacker-provided decryptor to fail for at least one paying victim. The firm reverse-engineered the malware and released an open-source decryptor to recover files affected by this issue, provided victims have the decryption key.
An update dated 27 October 2020 said RansomEXX affected the Pernambuco state court system in Brazil (TJPE). The incident reportedly used the .tjpe911 extension and the ransom note !NEWS_FOR_TJPE!.
Researchers discovered a new Linux-targeting file-encrypting Trojan and assessed it to be a Linux build of the RansomEXX ransomware family. Their analysis found strong similarities with previously known Windows RansomEXX samples in code structure, encryption routines, and ransom note wording.
The report assessed with high probability that a recent ransomware attack against a Brazilian government institution involved another RansomEXX variant, based on a ransom note nearly identical to the analyzed Linux sample.
Researchers said the Windows PE sample with hash fcd21c6fca3b9378961aa1865bee7ecb was used in the Texas Department of Transportation ransomware attack, identifying it as a RansomEXX incident.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
id-ransomware.blogspot.com
Open sourcesecurityintelligence.com
Open sourcesentinelone.com
Open sourcebleepingcomputer.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.