RAA encryptor
Aliases: RAA, RAA SEP
- First seen
- 2016-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:39:09
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
RAA encryptor is a ransomware family written entirely in JavaScript, distributed primarily through email attachments. It is known to have links with the Pony credential-stealer, enhancing its capabilities beyond simple file encryption.
Reports & references
- reaqta.com — Raa Ransomware Delivering Pony (report)
- bleepingcomputer.com — The New Raa Ransomware Is Created Entirely Using Javascript (report)
- id-ransomware.blogspot.com — Raa Ransomware Aes 256 039 250 (report)