Netskope Threat Labs

Ranzylocker

ATP Sandbox Adv. HeuristicsAV

Ranzylocker refers to detections of the Ranzy Locker ransomware operation, which emerged in 2021 and built on the leaked ThunderCrypt code base. Its affiliates targeted organizations through remote access services and spam, and researchers noted its callback ransom notes and leak site pressure.

First seen
April 2022
Last seen
October 2026
RanzyLocker
Alert Name
Gen:Variant.Ransom.RanzyLocker.5
Win32.Ransomware.Ranzylocker
Win32.Ransomware.RanzyLocker