RA

Ransomexx Ransomware

Tracked

Threat actor group tracked in the global ransomware database ยท Last disclosure: Jun 20, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
24
Total Victims
0.1% of all tracked
17
Countries Targeted
10
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Ransomexx and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Ransomexx is a ransomware family responsible for targeting 24 companies across 17 countries in mid-2020, making it active both widely and significantly during the year.

Who Ransomexx is

RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.

Recorded activity

Disclosures attributed to Ransomexx in this database run from April 2024 to June 2026, totalling 24 victims โ€” 0.1% of everything tracked here. Ransomexx has listed victims in 17 countries in this database, most often United States, followed by India and Japan. The sectors appearing most in its listings are Business Services, Technology, Healthcare.

Tooling observed in Ransomexx operations

  • LaZagne
  • Mimikatz
  • ProcDump
  • BCDEdit
  • Cobalt Strike

Software reported in use by Ransomexx. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

YARA detection rules

ransomexx.yar
/*
RansomEXX / Defray777 ransomware
*/

rule RansomEXX_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.ransomexx"
        description = "Detects RansomEXX ransom note"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $s1 = "RansomEXX" ascii nocase
        $s2 = "RANSOM_NOTE.txt" ascii nocase
        $s3 = ".ransom" ascii nocase
        $s4 = "Defray777" ascii nocase

    condition:
        any of them
}

rule RansomEXX_PE
{
    meta:
        author = "ransomware.live"
        family = "ransomware.ransomexx"
        description = "Detects RansomEXX ransomware executable"
        date = "2026-05-04"
        severity = 9
        score = 90

    strings:
        $s1 = "RansomEXX" ascii wide
        $s2 = "Defray777" ascii nocase
        $s3 = "/proc/sys/vm/drop_caches" ascii

    condition:
        (uint16(0) == 0x5A4D or uint32(0) == 0x464C457F) and 2 of them
}

Community-contributed rules for Ransomexx, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Ransomexx is a ransomware threat group that has disclosed 24 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Ransomexx in our dataset dates to April 2024.

Geographically, Ransomexx has targeted organisations in 17 countries. The most frequently targeted nation is United States with 5 victim organisations. Other heavily targeted nations include India, Japan, France.

Industry-wise, Ransomexx shows a concentration in the Business Services, Technology, Healthcare sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Ransomexx likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 24 most recent of the 24 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 24 of 24)

# Organization Country Sector Date
1 Go2Joy (go2joy.vn) go2joy.vn ๐Ÿ‡ป๐Ÿ‡ณ Vietnam Hospitality and Tourism Jun 20, 2026
2 GoTip gotip.jp ๐Ÿ‡ฏ๐Ÿ‡ต Japan Business Services Apr 17, 2026
3 SOGO Auction sogocorporation.com ๐Ÿ‡ฏ๐Ÿ‡ต Japan Business Services Apr 17, 2026
4 ADDA (adda.io) adda.io ๐Ÿ‡ฎ๐Ÿ‡ณ India Technology Mar 7, 2025
5 Grupo Vargas grupovargas.com VE Healthcare Mar 4, 2025
6 Lakeshore Title Agency lstitle.com ๐Ÿ‡บ๐Ÿ‡ธ United States Financial Services Mar 4, 2025
7 Makesworth Accountants makesworth.co.uk ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom Financial Services Mar 4, 2025
8 Retemex Retemex.mx ๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico Telecommunication Sep 14, 2024
9 Brontoo Technology Solutions brontoo.com ๐Ÿ‡ฎ๐Ÿ‡ณ India Technology Aug 10, 2024
10 nursing.com nursing.com ๐Ÿ‡บ๐Ÿ‡ธ United States Healthcare Aug 3, 2024
11 LITEON liteon.com ๐Ÿ‡น๐Ÿ‡ผ Taiwan Technology Jul 26, 2024
12 Planet Group International planetgroupint.com ๐Ÿ‡บ๐Ÿ‡ธ United States Technology Jul 26, 2024
13 Wagner-Meinert โ€” Business Services Jul 12, 2024
14 Asteco asteco.com ๐Ÿ‡ฆ๐Ÿ‡ช UAE Business Services Apr 22, 2024
15 Badan Urusan Logistik ๐Ÿ‡ฎ๐Ÿ‡ฉ Indonesia Transportation/Logistics Apr 22, 2024
16 Bombardier Recreational Products brp.com ๐Ÿ‡จ๐Ÿ‡ฆ Canada Manufacturing Apr 22, 2024
17 Consorci Sanitari Integral csi.cat ๐Ÿ‡ช๐Ÿ‡ธ Spain Healthcare Apr 22, 2024
18 Diagnostica Stago stago.fr ๐Ÿ‡ซ๐Ÿ‡ท France Healthcare Apr 22, 2024
19 DVision Architecture dvisionarchitecture.com ๐Ÿ‡ฎ๐Ÿ‡น Italy Business Services Apr 22, 2024
20 Jacobs Farm / Del Cabo delcabo.com ๐Ÿ‡บ๐Ÿ‡ธ United States Agriculture and Food Production Apr 22, 2024
21 Ministry of Defense of Peru ๐Ÿ‡ต๐Ÿ‡ช Peru Public Sector Apr 22, 2024
22 Ruwac Industrial Vacuums ruwac.com ๐Ÿ‡บ๐Ÿ‡ธ United States Manufacturing Apr 22, 2024
23 Telecommunications Services of Trinidad and Tobago tstt.co.tt ๐Ÿ‡น๐Ÿ‡น Trinidad and Tobago Business Services Apr 22, 2024
24 United Carton Industries Company ucic.com.sa ๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia Manufacturing Apr 22, 2024

Frequently Asked Questions

What is Ransomexx ransomware?

Ransomexx is a ransomware threat group that has claimed 24 victims since its first known activity in April 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Ransomexx attacked?

Ransomexx has claimed 24 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, India, Japan, France.

Which countries does Ransomexx target?

Ransomexx has attacked organizations in 17 countries. The top targeted countries are: United States, India, Japan, France.

Which industries does Ransomexx target?

Ransomexx most frequently targets the Business Services, Technology, Healthcare sectors based on victim disclosures in our database.

Is Ransomexx still active?

Ransomexx's most recent victim disclosure in our database was on June 20, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.