DefrayX (Hive0091) is known for RansomExx ransomware operations targeting the healthcare and manufacturing sectors.
Analyst brief
DefrayX (Hive0091) is a threat actor active since 2018, known primarily for their RansomExx ransomware operations. The group targets the healthcare and manufacturing sectors, deploying ransomware on both Linux and Windows operating systems. Their toolkit includes RansomExx, PyXie RAT, Vatet loader, and Defray ransomware, indicating a diverse malware arsenal. Defenders should focus on monitoring Linux environments, detecting multi-stage loader chains, and implementing comprehensive detection rules for the group's varied malware suite.
DefrayX
Hive0091
unknown
DefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for Windows. The group has been active since 2018 and has targeted various sectors, including healthcare and manufacturing. They have also developed other malware strains such as PyXie RAT, Vatet loader, and Defray ransomware.