SunCrypt emerged as a ransomware-as-a-service operation linked to the broader Maze cartel, a loose collaboration associated with Maze, LockBit, and Ragnar Locker. Reporting indicated SunCrypt described itself as operationally independent while maintaining two-way communications with Maze and sharing revenue from successful attacks, and technical analysis found SunCrypt contacting infrastructure previously tied to Maze. Maze later denied any formal relationship, but the overlap added to evidence that ransomware groups were sharing infrastructure, resources, or affiliate support while publicly distancing themselves from one another.
Subsequent analysis showed SunCrypt remained active and continued to mature its malware despite lower public visibility. Newer variants added capabilities to terminate processes, stop services, prepare systems for encryption, wipe event logs, and self-delete after execution, while retaining faster threaded encryption, targeting of local volumes and network shares, and safeguards to avoid making systems unbootable. Victim reporting and security research indicated the group was still compromising organizations, including a case identified by Minerva Labs involving Migros, underscoring that SunCrypt persisted as an evolving ransomware threat rather than disappearing after its initial rise.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Reporting based on ID-Ransomware submissions indicated that SunCrypt was still encrypting victims in 2022, though visible activity appeared limited. The reporting suggested the operators may have been focusing on high-value targets while keeping negotiations private.
Analysis of a newer 2022 SunCrypt variant found added capabilities including process termination, service stopping, machine cleanup, event log wiping, and self-deletion after encryption. The malware also retained faster threaded encryption, network-share encryption, and an allowlist to avoid breaking systems.
SunCrypt became prominent in mid-2020 as a ransomware-as-a-service operation. It was described as an early adopter of triple extortion, combining file encryption, data leak threats, and DDoS pressure against non-paying victims.
Submission statistics to ID-Ransomware indicated that the SunCrypt ransomware family began operating in October 2019.
Minerva Labs identified Migros, Switzerland's largest supermarket chain, as one of SunCrypt's recent victims. The finding was cited as evidence that the group was still actively hitting organizations.
Maze later told BleepingComputer that it had no connection with SunCrypt and said the claimed affiliation was false. Maze said it believed SunCrypt used the claim as a PR tactic to pressure victim companies.
A SunCrypt sample analyzed by BleepingComputer was found contacting 91.218.114[.]31, an IP previously used by Maze during attacks, and Advanced Intel also said SunCrypt connected to 91.218.114[.]30. The overlap suggested shared infrastructure or white-labeled ransomware technology between the operations.
SunCrypt told BleepingComputer by email that it was a new member of the Maze ransomware cartel while remaining an independently run operation. It said cartel members had two-way communications with Maze and shared revenue from successful attacks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceblog.minerva-labs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.