DefrayX

Aliases: Hive0091

First seen
2018-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:09:37

Targeted industries: healthcare-and-pharmaceutical manufacturing

Context

DefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for Windows. The group has been active since 2018 and has targeted various sectors, including healthcare and manufacturing. They have also developed other malware strains such as PyXie RAT, Vatet loader, and Defray ransomware.

Reports & references

  • securityaffairs.co — Ransomexx Ransomware Rust Language (report)
  • research.checkpoint.com — 28Th November Threat Intelligence Report (report)
  • securityintelligence.com — Ransomexx Upgrades Rust (report)

External references