Defray

Aliases: Glushkov

First seen
2017-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 12:59:43

Targeted industries: healthcare-and-pharmaceutical

Targeted regions: country_code:gb country_code:us

Context

Defray is ransomware that appeared in 2017, and is targeted ransomware, mainly on the healthcare vertical. The distribution of Defray has several notable characteristics: According to Proofpoint: " Defray is currently being spread via Microsoft Word document attachments in email The campaigns are as small as several messages each The lures are custom crafted to appeal to the intended set of potential victims The recipients are individuals or distribution lists, e.g., group@ and websupport@ Geographic targeting is in the UK and US Vertical targeting varies by campaign and is narrow and selective "

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Defray_Auto (yara-rule)

Reports & references

  • secureworks.com — Gold Dupont (report)
  • jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
  • youtube.com — Watch (report)
  • Palo Alto Unit 42 — 4 (report)
  • Palo Alto Unit 42 — Vatet Pyxie Defray777 (report)
  • Palo Alto Unit 42 — 3 (report)
  • Palo Alto Unit 42 — 5 (report)
  • Trend Micro — Weaponizing Open Source Software For Targeted Attacks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Defray (report)
  • bleepingcomputer.com — Government Software Provider Tyler Technologies Hit By Ransomware (report)
  • Palo Alto Unit 42 — 2 (report)
  • threatvector.cylance.com — Threat Spotlight Defray Ransomware Hits Healthcare And Education (report)
  • proofpoint.com — Defray New Ransomware Targeting Education And Healthcare Verticals (report)
  • proofpoint.com — New Defray Ransomware Targets Education And Healthcare Verticals (report)

External references