Skip to content

Ransomware

RansomEXX

aka Defray777

According to SentineOne, RansomEXX (aka Defray, Defray777), a multi-pronged extortion threat, has been observed in the wild since late 2020.

RansomEXX, also known as Defray777, is a Linux ransomware operated by GOLD DUPONT.

Background

SentinelOne reports that RansomEXX (also called Defray and Defray777), a multi-faceted extortion threat, has been active in the wild since late 2020. It has been linked to intrusions affecting the Texas Department of Transportation, Groupe Atlantic, and other large organizations. The family exists in both Windows and Linux variants and is notable for its narrow, highly selective targeting.


Source: Malpedia (Fraunhofer FKIE).