Opinion50 Things I learned about the RansomEXX group

50 Things I learned about the RansomEXX group

AboveL A redacted note issued by RansomEXX

Shiva Parasram created this list of factoids about the ransomware group RansomEXX and published it to his LinkedIn page. It is reproduced here with his kind permission.

  1. 🎯 Emergence: RansomEXX came into the spotlight around 2020, primarily targeting notable organizations.
  2. 📛 Alias: They are also referred to as Defray777, stemming from a unique identifier in their ransomware code.
  3. 🔒 Encryption Techniques: RansomEXX employs strong encryption, making it difficult to restore files without their decryptor.
  4. 🌎 Global Attacks: While selective, they have targeted entities across various continents.
  5. 🔍 Specific Targets: They have a penchant for large corporations and public sector organizations.
  6. 🖥️ Hands-on Approach: RansomEXX prefers manual operations inside a network over automated techniques.
  7. 💽 Data Theft: Before encrypting systems, they often steal sensitive data.
  8. 📢 Double Extortion: They not only encrypt but threaten to leak stolen data if ransoms aren’t paid.
  9. 📜 Personalized Notes: Their ransom communications are typically customized based on the victim.
  10. 💰 RaaS: They do operate independently but have been known to operate as a RaaS (Ransomware-as-a-Service) model.
  11. 🎣 Phishing Mastery: Deceptive emails are often their initial entry method into networks.
  12. 🔗 Exploit Chains: They often chain together multiple software vulnerabilities for deeper access.
  13. 🖇️ Unpatched Software: RansomEXX capitalizes on outdated and vulnerable software, especially public-facing applications.
  14. 🧰 Diverse Toolkit: Their arsenal includes a mix of custom and off-the-shelf tools.
  15. 🔑 Mimikatz: A favored tool for credential dumping and privilege escalation.
  16. ⚡ PowerShell Empire: A post-exploitation framework granting wide-ranging capabilities.
  17. 💼 Cobalt Strike: Originally a legitimate pen-testing tool, it’s now a favorite among attackers.
  18. 🌐 Lateral Tactics: Tools like PsExec help them traverse laterally across compromised networks.
  19. 🔍 Network Recon: They actively map networks using tools like BloodHound.
  20. ☁️ Data Movement: Rclone can be misused for moving data stealthily to cloud storage.
  21. 🔍 Active Directory: They mine AD data using tools like AdFind for understanding permissions and relations.
  22. 🚪 Misconfigurations: They exploit insecure settings or exposed services.
  23. 📊 Target Research: Before an attack, they spend time researching potential victims for maximum impact.
  24. 💰 High Ransoms: Their demands can be exorbitant, reflecting their target’s perceived ability to pay.
  25. 📈 Tailored Operations: RansomEXX customizes their attack methods based on the target’s environment.
  26. 🛡️ Avoiding Detection: They use “living off the land” tactics to blend into environments.
  27. 🚷 No Known Decryptor: As of the last known update, no public decryption tool can counter RansomEXX.
  28. 📞 Communication Channels: They often provide a communication channel for ransom negotiations.
  29. 🔥 Destruction: In some cases, they may try to delete backups or disrupt recovery efforts.
  30. 🌍 Varied Victims: Targets have included healthcare, government entities, and critical infrastructure.
  31. 🔄 Network Propagation: Once inside, they work to gain higher privileges and access more systems.
  32. 🔐 Credential Theft: Capturing credentials is a priority to facilitate movement and persistence.
  33. 🛑 Stopping Security: They might attempt to disable security software or services.
  34. 🗂️ File Types: They target a broad range of file extensions, ensuring vital data gets encrypted.
  35. ⌛ Dwell Time: They can remain in networks for days to weeks before launching the ransomware.
  36. 📝 Detailed Notes: Ransom notes often provide detailed payment instructions using cryptocurrencies.
  37. ⚖️ Negotiations: Some victims have successfully negotiated lower ransoms.
  38. 🚫 Decryption Issues: Even after payment, decryption isn’t always smooth, with occasional technical issues.
  39. 🌐 Network Disruptions: Their operations can disrupt not just endpoints but entire networks.
  40. 🚫 No Warranty: Paying the ransom doesn’t guarantee data safety or prevent future attacks.
  41. 🕵️ Stealth: They often clean logs or use encrypted channels to avoid detection.
  42. 📦 Payload Delivery: Various methods, from malicious attachments to drive-by downloads, are used.
  43. 📡 Command & Control: They establish robust C2 communications to control compromised systems.
  44. 🛡️ Backup Importance: The best defense against their attack is having secure and isolated backups.
  45. 🚫 No Discrimination: Despite being selective, no industry is truly safe from their attention.
  46. 🖲️ VPN Exploits: Vulnerable VPNs have been a notable point of entry.
  47. 📅 Continuous Evolution: Their techniques and tools evolve to counteract defenses.
  48. 💡 Awareness: Training staff to spot phishing and suspicious behavior can prevent initial access.
  49. 🚀 Rapid Response: Quick detection and response can mitigate the damage they cause.
  50. 🔒 Layered Defense: Employing a multi-layered security approach is crucial in defending against groups like RansomEXX.

Related Posts

An app to make co-parenting more accountable

An app to make co-parenting more accountable

“I built Zuko because everyday matters could become conflict when communication was scattered or misunderstood.”
Read More
In a US university film lab, a Trini is working and learning

In a US university film lab, a Trini is working and learning

Most people are pressing buttons. The work is in defining what the buttons do.
Read More
The Global Lense – The one about data and tech stack sovereignty

The Global Lense – The one about data and tech stack sovereignty

Most recent technology development appears to be companies outside the region tapping the market within the region.
Read More
Declaring independence from mobile roaming

Declaring independence from mobile roaming

Most modern smartphones, even those with a physical SIM tray, will also accept an e-SIM.
Read More
Intellico introduces AI agency service with 150 agents

Intellico introduces AI agency service with 150 agents

The proper use of AI can help flatten the world and make opportunities available to small nations that they could not achieve previously.
Read More
CANTO summarises 2026 conference discussions

CANTO summarises 2026 conference discussions

Government leaders from Estonia, Curaçao, Jamaica, the Cayman Islands, and St. Vincent and the Grenadines pressed the case for closer collaboration between the public and private sectors on national digital...
Read More
Effectively incorporate AI into your business

Effectively incorporate AI into your business

A tool can save an employee 30 minutes and still be a poor business decision.
Read More
Urgency, awareness needed to combat sextortion

Urgency, awareness needed to combat sextortion

While social platforms make it easy for crimes to cross borders and infiltrate households, law enforcement remains limited by the transnational agreements that enable effective policing across borders.
Read More
What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you)

What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you)

AI can generate a chronology of events from a stack of documents that would take a paralegal hours to work through. What they cannot do is guarantee accuracy.
Read More
Hands on: BOSGAME VTA-439

Hands on: BOSGAME VTA-439

I chose Ubuntu to demonstrate that an enterprise Linux distribution works well on the system.
Read More
An app to make co-parenting more accountable An app to make co-parenting more...
In a US university film lab, a Trini is working and learning In a US university film lab,...
The Global Lense – The one about data and tech stack sovereignty The Global Lense – The one...
Declaring independence from mobile roaming Declaring independence from mobile roaming
Intellico introduces AI agency service with 150 agents Intellico introduces AI agency service with...
CANTO summarises 2026 conference discussions CANTO summarises 2026 conference discussions
Effectively incorporate AI into your business Effectively incorporate AI into your business
Urgency, awareness needed to combat sextortion Urgency, awareness needed to combat sextortion
What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you) What Trinidad and Tobago’s new AI...
Hands on: BOSGAME VTA-439 Hands on: BOSGAME VTA-439

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Oldest
Newest Most Voted

RELATED POSTS