LIVE
LATEST THREAT: Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure THREAT ALERT ACTIVE
Intelligence DB / Group Profile RansomExx

RansomExx: Long-Running Enterprise Ransomware Group Targeting Critical Infrastructure and Government

RansomExx is one of the oldest continuously active ransomware operations, with confirmed victims across government, critical infrastructure, healthcare, and education in North America, Europe, and Latin America. This profile covers the group's history, Linux/Windows dual-platform tooling, and current 2026 activity.

By Ransomware Tracker ·
RansomExxransomwareLinuxVMware ESXigovernmentcritical-infrastructureenterprisedouble-extortion2026Defray777group-profile
Threat Level
8/10
Sectors Targeted
government
healthcare
education
manufacturing
critical-infrastructure
transportation
Ransomware Family
RansomExx

Overview

RansomExx — also tracked as Defray777, Target777, and Ransom X — is a closed (non-RaaS) ransomware operation that has been active since at least 2018. Unlike the affiliate-driven RaaS model that dominates the current threat landscape, RansomExx operates with a small core team that conducts intrusions directly rather than using external affiliates. This gives the group greater operational security but limits their throughput compared to high-volume RaaS operators like LockBit or RansomHub.

What RansomExx lacks in volume, it compensates for in targeting. The group consistently pursues large enterprise targets — particularly government agencies, critical infrastructure operators, and multinational corporations — where the combination of high-value data, limited ability to tolerate operational disruption, and legacy IT environments creates favourable conditions for a ransom negotiation. Confirmed victims have included government agencies in the United States, Brazil, and Ecuador, major transportation authorities, and healthcare organisations.

The group achieved sustained attention in 2020-2021 with high-profile attacks against Konica Minolta, Tyler Technologies (a provider of government software used by US courts and municipalities), the Texas Department of Transportation, and the Scottish Environmental Protection Agency. The pattern of targeting government IT supply chain vendors — organisations whose compromise affects downstream government customers — has continued through 2025-2026.

Technical Capabilities

Dual-Platform Tooling

RansomExx is notable for maintaining both Windows and Linux encryptors, with the Linux variant specifically targeting VMware ESXi hosts for mass virtual machine encryption. The group’s Linux capability predates the broader shift toward ESXi targeting that has characterised ransomware operations since 2021-2022 — they deployed Linux payloads against ESXi infrastructure before most other operations had developed the capability.

Windows variant characteristics:

  • Compiled as a standard Windows PE executable
  • Uses mbedTLS for encryption (AES-256 in ECB mode per early analysis; later samples moved to other modes)
  • Destroys shadow copies via vssadmin.exe delete shadows /all /quiet
  • Terminates security software and backup processes before encryption
  • Drops ransom note as !readme!.txt with victim-specific content (the ransom note is uniquely generated per victim with their name and organisation)
  • Targets network shares in addition to local drives

Linux/ESXi variant characteristics:

  • ELF64 binary targeting RHEL/CentOS and VMware ESXi
  • Encrypts .vmdk, .vmx, .vmxf, .vmsd, .vmsn, .vmss, .nvram, .vmem files — the complete VMware virtual machine footprint
  • Uses ESXi vim-cmd to enumerate and gracefully power down VMs before encryption, preventing file-lock conflicts
  • No command-and-control dependency during encryption phase — fully autonomous once deployed
  • Ransomware binary embedded with victim-specific key material, preventing generic decryption

Initial Access and Intrusion TTPs

RansomExx does not rely on a single initial access technique. Observed access vectors across documented intrusions include:

Unpatched public-facing vulnerabilities: The group has exploited vulnerabilities in Citrix ADC (CVE-2019-19781), Pulse Secure VPN, and similar perimeter appliances. Their targeting of government networks, which often lag on patching, makes this a consistent access path.

Compromised RDP credentials: Purchased from initial access brokers or obtained via credential stuffing of VPN and remote access portals.

Spear-phishing with malicious documents: Some intrusions begin with phishing campaigns targeting specific organisations, particularly in the early stages of a new campaign.

Supply chain compromise: The group’s targeting of government IT vendors (Tyler Technologies being the highest-profile example) reflects an understanding that vendor networks provide access to downstream targets without requiring direct exploitation of those targets.

Post-Compromise Activity

RansomExx intrusions are characterised by extended dwell time — the group typically spends days to weeks inside a network conducting reconnaissance, privilege escalation, and data exfiltration before deploying the encryptor. This extended timeline is consistent with their targeting of large enterprises where network reconnaissance is necessary to maximise encryption impact.

Observed post-compromise tools include:

  • Cobalt Strike: Beaconing and lateral movement
  • Mimikatz: Credential harvesting from LSASS
  • WinPEAS / LinPEAS: Local privilege escalation enumeration
  • AdFind / BloodHound: Active Directory reconnaissance
  • Rclone / MEGAsync: Data exfiltration to cloud storage for double extortion
  • PsExec / WMI: Lateral movement and remote encryptor deployment

Double Extortion and Data Leak Operations

RansomExx operates a data leak site — accessible via Tor — where they publish exfiltrated data from victims who refuse to pay. The site follows the standard double extortion model: victim data is published in stages to maximise ransom pressure, with teaser content released first and full datasets threatened if payment is not received.

Unlike some operators who maintain active negotiation services with professional ransom negotiators on retainer, RansomExx communications tend toward directness. The group provides victims with a private contact link for negotiation and sets a deadline, typically 7-14 days, before publishing. They have followed through consistently on data publication threats.

2025-2026 Activity

RansomExx maintained a lower public profile through parts of 2024-2025 but remained active. Confirmed 2025-2026 activity includes:

  • Several government and public sector organisations in Latin America, consistent with the group’s historical regional focus
  • Healthcare sector targets in the United States, where legacy OT/IT integration in hospital environments creates extended lateral movement opportunities
  • Continued ESXi-targeting campaigns that take advantage of unpatched CVEs in ESXi management interfaces

The group has not adopted the RaaS model or significantly scaled their operations to compete with high-volume operators. Their current volume — estimated at 10-20 public victims per year — reflects deliberate targeting rather than broad spraying.

Indicators and Detection

File extension: Encrypted files receive a random eight-character extension that is unique per victim (e.g., .pjawAE3c) — this differs from groups that use a fixed extension and makes YARA rules based on extension less useful.

Ransom note: !readme!.txt dropped in encrypted directories. Victim-specific content; generic YARA matching on content patterns is more reliable than exact string matching.

Process termination: Bulk termination of vmware-vmx.exe, sqlservr.exe, mssqlserver, backup agent processes.

ESXi command execution: vim-cmd vmsvc/getallvms and vim-cmd vmsvc/power.off observed during pre-encryption VM shutdown.

SIGMA detection opportunity: The combination of LSASS access, shadow copy deletion, and ESXi management command execution within a 24-hour window is a strong behavioural indicator. See the SOC Analyst Hub for detection rules targeting these sequences.

Attribution and Threat Actor Assessment

RansomExx has been attributed to a financially-motivated threat actor operating in the Eastern European cybercriminal ecosystem, though definitive nation-state attribution has not been established. IBM Security X-Force and CrowdStrike have both tracked the group under their respective naming conventions. The closed-team operating model and sustained multi-year activity suggest a professional criminal organisation rather than an opportunistic operation.

The group’s targeting of government agencies has raised questions about potential state nexus — particularly given the focus on Latin American government targets — but available evidence supports financial motivation as the primary driver. Ransom demands and payment records where available are consistent with enterprise-scale financial crime rather than intelligence collection objectives.

// Related Intelligence
Group Profile

Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure

Group Profile

Embargo Ransomware: Rust-Based RaaS Targeting Enterprise and Healthcare

Group Profile

Spirals Ransomware: New Group Completes Full Attack Chain in Under 24 Hours