Netskope Threat Labs

DearCry

ATP Sandbox Adv. HeuristicsAV

DearCry (a.k.a. DoejoCrypt) is a ransomware family observed in March 2021 that infected unpatched Microsoft Exchange servers through the ProxyLogon vulnerabilities. After exploitation, the malware encrypts files and demands payment, and its campaigns showed how quickly ransomware crews weaponize newly disclosed remote code execution flaws in internet facing infrastructure. Organizations that patched Exchange promptly avoided the family, and its detections usually indicate an unpatched or previously breached mail server.

First seen
March 2022
Last seen
October 2026
Dearcry
Alert Name
Gen:Heur.Mint.SP.Ransom.Dearcry.1
Win32.Ransomware.DearCry