ZeroHour

ransomexx

ransomware group · aka RansomEXX, Ransom X, REX, Defray777 · unknown · active since 2018 (as Ransom X/Defray777); RansomEXX branding reported from 2020

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
1
All-time (tracked)
70since 2021-09-09
Last post
06-20 16:53UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

RansomEXX (also tracked as Ransom X, REX, and Defray777) is a double-extortion ransomware family observed since 2018 and notable for releasing one of the first widely covered Linux encryption variants in mid-2020. Publicly reported victims include the Texas Department of Transportation and Konica Minolta, both in 2020. Proofpoint tracks the associated threat actor as TA1650, which has also been observed deploying the Monti (Mirai-variant) botnet alongside ransomware on Linux hosts. Vendor research (Trend Micro, 2021) documented use of the FortiOS vulnerability CVE-2018-13379 for initial access, and IBM reported use of ZeroLogon (CVE-2020-1472) for privilege escalation in the Defray777 era. Per this dashboard's tracking, current leak-site activity is low, with one victim listed in the past 90 days and the most recent post on 2026-06-20.

Tactics & tooling
  • Double-extortion model: encryption combined with publication on a dedicated leak site
  • Windows and Linux encryption binaries, including an early prominent Linux variant (2020)
  • Initial access via Fortinet FortiOS CVE-2018-13379 (vendor reporting, 2021)
  • Privilege escalation using ZeroLogon (CVE-2020-1472) (vendor reporting, 2020)
  • Hands-on-keyboard intrusions linked to the actor tracked as TA1650 (Proofpoint)
  • Observed deploying Monti, a Mirai-variant botnet, on compromised Linux hosts alongside ransomware (Proofpoint, 2022)
Targeted sectors
GovernmentTransportationTechnology & ManufacturingHealthcareFinancial & Professional Services
Notable public victims

Texas Department of Transportation (TxDOT), 2020 (public reporting), Konica Minolta, 2020 (public reporting), Lite-On Technology (LITEON), listed on group leak site (dashboard tracking), Go2Joy, listed on group leak site (dashboard tracking), ADDA, listed on group leak site (dashboard tracking), nursing.com, listed on group leak site (dashboard tracking), SOGO Auction, listed on group leak site (dashboard tracking)

CVEs linked to their intrusions
Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Ultrapar Participações S.A. · Sep 9, 2021
Vistra · Sep 9, 2021
Indura SA · Sep 9, 2021
Soluzioni Infrastrutturali Telefoniche ed Elettriche S.p.A. · Sep 9, 2021
CalAmp (NASDAQ: CAMP) · Sep 9, 2021
Pertamina EP · Sep 9, 2021
Consiglio Nazionale del Notariato · Sep 9, 2021
Ajuntament de Castelló · Sep 9, 2021
Nobiskrug · Sep 9, 2021
Samvardhana Motherson Peguform · Sep 9, 2021
Wallace & Carey · Sep 9, 2021
STEMCOR · Sep 9, 2021
Universal Assistance S.A. · Sep 9, 2021
WT Microelectronics · Sep 9, 2021
Walsin · Sep 9, 2021
Corporación Nacional de Telecomunicación · Sep 9, 2021
Liberty Group & ForHousing · Sep 9, 2021
Ermenegildo Zegna Holding · Sep 9, 2021Discover the world of Ermenegildo Zegna Group, a family company guided by ethical entrepreneurship that leads the fashion sector in a sustainable way.
Gigabyte Technology · Sep 9, 2021Gigabyte Technology is a Taiwanese manufacturer and distributor of computer hardware. Gigabyte's principal business is motherboards.
American Megatrends International · Sep 9, 2021Founded in 1985 and known worldwide for AMIBIOS®, the mission of AMI is to power, manage and secure the world’s connected digital infrastructure by providing best-in-class UEFI and remote management firmware, security solutions, development tools and utilities to top-tier manufacturers of desktop, server, mobile and embedded/IoT systems. Source codes are inside.

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .