Ranzy Locker, formerly ThunderX, is a ransomware group known for double extortion tactics.
Analyst brief
Ranzy Locker, formerly known as ThunderX, is a cybercrime group conducting ransomware operations with a focus on double extortion. They target victims who refuse to pay the ransom by publishing sensitive data on their dedicated darknet leak site. The group's key TTPs include using an iteratively improved ransomware variant and sharing Tor infrastructure with Ako Ransomware, suggesting possible merger or cartel-style cooperation. Defenders should prioritize robust offline backups to counter data leak threats and monitor for shared indicators or evolving TTPs stemming from potential group collaborations.
ranzy
crime
Ranzy Locker, Former known as ThunderX. The group hosting a data leak site in the darknet where they posting sensitive information of victims who do not pay the ransom. ThunderX was launched at the end of August 2020. Soon after launching, weaknesses were found in the code, that allowed decrypting the files that the malware encrypted. The group has fixed the code and publish a new version, then released it under the name Ranzy Locker. The Tor onion URL used by the Ranzy Leak site is the same as the one used by Ako Ransomware. The use of the same URL could indicate that both groups merged, or they are cooperating similarly to the Maze cartel.
How does the Ranzy Locker ransomware group threaten victims who do not pay the ransom?+
Ranzy Locker publishes sensitive information of victims who do not pay the ransom on their dedicated data leak site in the darknet.
What sign of connection has been observed between Ranzy Locker and Ako Ransomware?+
The Tor onion URL used by the Ranzy Locker leak site is the same as the one used by Ako Ransomware, suggesting that both groups may have merged or are cooperating.