Defray
Aliases: Glushkov
- First seen
- 2017-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 12:59:43
Targeted industries: healthcare-and-pharmaceutical
Targeted regions: country_code:gb country_code:us
Context
Defray is ransomware that appeared in 2017, and is targeted ransomware, mainly on the healthcare vertical. The distribution of Defray has several notable characteristics: According to Proofpoint: " Defray is currently being spread via Microsoft Word document attachments in email The campaigns are as small as several messages each The lures are custom crafted to appeal to the intended set of potential victims The recipients are individuals or distribution lists, e.g., group@ and websupport@ Geographic targeting is in the UK and US Vertical targeting varies by campaign and is narrow and selective "
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Defray_Auto (yara-rule)
Reports & references
- secureworks.com — Gold Dupont (report)
- jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
- youtube.com — Watch (report)
- Palo Alto Unit 42 — 4 (report)
- Palo Alto Unit 42 — Vatet Pyxie Defray777 (report)
- Palo Alto Unit 42 — 3 (report)
- Palo Alto Unit 42 — 5 (report)
- Trend Micro — Weaponizing Open Source Software For Targeted Attacks (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Defray (report)
- bleepingcomputer.com — Government Software Provider Tyler Technologies Hit By Ransomware (report)
- Palo Alto Unit 42 — 2 (report)
- threatvector.cylance.com — Threat Spotlight Defray Ransomware Hits Healthcare And Education (report)
- proofpoint.com — Defray New Ransomware Targeting Education And Healthcare Verticals (report)
- proofpoint.com — New Defray Ransomware Targets Education And Healthcare Verticals (report)