RansomExx — Ransomware Profile
RansomEXX began life in 2018 under the name Defray777 and was rebranded after analysts noticed a "ransom.exx" string inside its binaries, per Trend Micro's 2022 spotlight on the family. Trend Micro records that the family gained prominence in 2020 after a series of high-profile intrusions, and contemporaneous reporting that year tied it to victims including the Texas Department of Transportation, Konica Minolta, IPG Photonics, Tyler Technologies and Brazil's Superior Court of Justice; the operators stood up a data-leak site over the same period. Kaspersky's teardown of a November 2020 sample documented a Linux build of the family, an ELF binary using AES in ECB mode with an RSA-4096-wrapped key, which Trend Micro described as the first time a major Windows ransomware variant expanded to Linux, while CrowdStrike, which calls the operators Sprite Spider, documented the parallel push onto VMware ESXi hosts. Every build carries the victim organisation's name compiled straight into it, a marker of the reconnaissance-heavy, hands-on-keyboard intrusions Secureworks files under GOLD DUPONT alongside Vatet Loader, PyXie RAT and Cobalt Strike. Trend Micro telemetry covering March 2021 to March 2022 put the heaviest concentration in the United States, France and Brazil, and in manufacturing, education and banking. Microsoft reported in April 2025 that a cluster it designates Storm-2460 dropped RansomEXX after exploiting CVE-2025-29824, a Windows CLFS elevation-of-privilege zero-day, against victims that included US technology and real-estate firms and a Saudi retailer.Also tracked as
Defray777, Defray 2018, Target777, Ransom X, Sprite Spider, GOLD DUPONT
Recent claimed victims
- Go2Joy (go2joy.vn) 2026-06-20
- SOGO Auction 2026-04-17
- GoTip 2026-04-17
Vendor research
- RansomEXX Trojan attacks Linux systems Kaspersky
- When Threat Actors Fly Under the Radar: Vatet, PyXie and Defray777 Unit 42
- Ransomware Spotlight: RansomEXX Trend Micro
- RansomExx Upgrades to Rust IBM X-Force
- Hypervisor Jackpotting, Part 1: CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact CrowdStrike
Countries linked to this actor
- Trinidad and Tobago targets