RAA encryptor

Aliases: RAA, RAA SEP

First seen
2016-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:39:09

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

RAA encryptor is a ransomware family written entirely in JavaScript, distributed primarily through email attachments. It is known to have links with the Pony credential-stealer, enhancing its capabilities beyond simple file encryption.

Reports & references

  • reaqta.com — Raa Ransomware Delivering Pony (report)
  • bleepingcomputer.com — The New Raa Ransomware Is Created Entirely Using Javascript (report)
  • id-ransomware.blogspot.com — Raa Ransomware Aes 256 039 250 (report)

External references