Researchers identified FuxSocy Encryptor as a ransomware family that closely imitates the defunct Cerber strain in both presentation and parts of its internal logic. The malware encrypts victim files with AES, scrambles or renames filenames in Cerber-like patterns, drops ransom notes such as ***__READ___THIS__***.txt, and can change the desktop wallpaper after locking data. Analysis found it skips or prioritizes certain folders, includes anti-virtual-machine checks, and in some variants partially encrypts files beginning at offset 0x708, a technique that still leaves many documents unusable.
The operators initially directed victims to make contact through qTox/ToxChat rather than a Tor payment portal, later shifting some variants to email addresses including king-size_banana@thesecure.biz and fuxsocy@cockl.li. Reporting on later samples shows the family remained active in subsequent years with variants using extensions such as .b58d, while likely relying on common intrusion routes including exposed RDP, phishing emails, malicious attachments, fake downloads, exploits, malvertising, and trojanized installers. No free decryptor was available in the early reporting, and victims were advised to recover from backups instead of paying the ransom.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
The ID Ransomware write-up says a January 4, 2023 FuxSocy variant used the ransom note name ***__READ___THIS__***.txt and the contact email king-size_banana@thesecure.biz. It also provides the SHA-256 hash of a sample from that variant.
An update in the ID Ransomware write-up documents a December 22, 2019 variant that appends the .b58d extension to encrypted files. The same update gives example encrypted and ransom-note filenames for that variant.
Michael Gillespie reported that FuxSocy begins encrypting files at offset 0x708 instead of encrypting entire files. The analysis noted this still rendered many documents unusable, though some images retained visible unencrypted regions.
Reverse engineering by Vitali Kremez found that FuxSocy borrowed Cerber's skipped-path logic, filename scrambling behavior, and similar wallpaper styling, while adding broader anti-VM checks. Reporting also noted that victims were directed to contact the operators through Tox/qTox rather than a Tor payment site.
BleepingComputer reports that MalwareHunterTeam discovered the FuxSocy ransomware in October 2019. Researchers found it closely imitated the defunct Cerber ransomware in appearance and parts of its internal logic.
The ID Ransomware write-up states that FuxSocy Encryptor activity was first noted in early October 2019. It describes the family as encrypting files and demanding payment for recovery.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.