lorenz
1 incidentes
0 paises
0 sectores
ransomware Ultimo: 2026-06-25
Lorenz is a financially motivated ransomware group first observed in February 2021. It is believed to be a rebranding of the sZ40 ransomware, which emerged in October 2020, and potentially shares code with ThunderCrypt ransomware from May 2017. Lorenz operates with human interaction, customizing its attacks for each target, and is known for its unique multi-stage double extortion model. This model involves exfiltrating data, then attempting to sell it to other threat actors or competitors before eventually publishing password-protected archives, and ultimately releasing the passwords publicly if ransom demands remain unmet. The group engages in "big-game hunting," primarily targeting larger organizations for significant ransom payments, typically ranging from $500,000 to $700,000, and sometimes millions.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
Argentina
Austria
Australia
Belgium
Brazil
Canada
Chile
China
Germany
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingOther Information ServicesReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing
URLs nuevas detectadas en IntelTracker