Description
Ranzylocker refers to detections of the Ranzy Locker ransomware operation, which emerged in 2021 and built on the leaked ThunderCrypt code base. Its affiliates targeted organizations through remote access services and spam, and researchers noted its callback ransom notes and leak site pressure.
Stats
- First seen
- April 2022
- Last seen
- October 2026
Also known as
RanzyLocker
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.RanzyLocker.5 |
| Win32.Ransomware.Ranzylocker |
| Win32.Ransomware.RanzyLocker |