lorenz logo

lorenz

1 incidentes 0 paises 0 sectores ransomware Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Lorenz is a financially motivated ransomware group first observed in February 2021. It is believed to be a rebranding of the sZ40 ransomware, which emerged in October 2020, and potentially shares code with ThunderCrypt ransomware from May 2017. Lorenz operates with human interaction, customizing its attacks for each target, and is known for its unique multi-stage double extortion model. This model involves exfiltrating data, then attempting to sell it to other threat actors or competitors before eventually publishing password-protected archives, and ultimately releasing the passwords publicly if ransom demands remain unmet. The group engages in "big-game hunting," primarily targeting larger organizations for significant ransom payments, typically ranging from $500,000 to $700,000, and sometimes millions.
Tecnicas MITRE
T1059, T1027, T1486, T1074, T1053, T1112

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustriaAustraliaBelgiumBrazilCanadaChileChinaGermany

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com