SunCrypt is a ransomware group that emerged around October 2019. It operates as a Ransomware-as-a-Service (RaaS) with a closed affiliate program. The group's primary motivation is financial gain, achieved by encrypting victim files and demanding ransom payments. SunCrypt distinguishes itself by pioneering triple extortion tactics, which involve not only data encryption but also threatening to publish stolen data on leak sites and launching Distributed Denial of Service (DDoS) attacks against organizations that refuse to pay. While SunCrypt has previously claimed association with the Maze ransomware cartel, this affiliation has been explicitly denied by the Maze group.
Tecnicas MITRE
T1486, T1078, T1047, T1566
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
United Arab EmiratesArmeniaAustraliaBelgiumBahrainBrazilCanadaSwitzerlandChinaGermany
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingCredit UnionsSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstruction