SunCrypt
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
SunCrypt is a ransomware group that operates under the alias SunCrypt and has been linked to Russian‑based infrastructure in open‑source reporting. The group was first observed in October 2019 and maintains a small affiliate program, indicating a distributed criminal model rather than a single centralized crew. Public research notes that SunCrypt primarily targets organizations in the technology and retail sectors, although its observed victims also include healthcare providers, educational institutions and a pharmacy nonprofit. The group’s stated objective is financial gain, achieved through ransom demands coupled with the threat of leaking stolen data on a dedicated leak site; there is no public evidence linking SunCrypt to espionage or purely disruptive aims beyond the pressure created by data exposure.
SunCrypt’s operational toolkit centers on its own ransomware payload, which has been updated to include capabilities for terminating processes and wiping artifacts to hinder forensic analysis. Initial access frequently begins with a TrickBot trojan infection of an employee workstation, a vector that historically precedes network‑wide ransomware deployment. Once inside, attackers place a PowerShell script named after the victim on the Windows domain controller and distribute a batch file to each endpoint; executing the batch file runs the PowerShell script, which launches the ransomware and encrypts files across the network. Prior to encryption, the operators exfiltrate unencrypted files, storing them for later leakage, and they leave a ransom note in HTML format that directs victims to a Tor‑based payment portal. The group also leverages infrastructure previously associated with Maze ransomware, such as certain command‑and‑control IP addresses, to facilitate post‑exploitation activities.
Publicly reported campaigns illustrate SunCrypt’s pattern of targeting diverse sectors while maintaining a consistent extortion approach. In 2020 the group compromised University Hospital New Jersey, leaking approximately forty‑eight thousand documents containing personal health identifiers after an employee’s TrickBot infection preceded the ransomware deployment. Also in 2020 SunCrypt encrypted the network of a North Carolina school district, stealing unencrypted data before releasing a five‑gigabyte archive when the ransom was not paid, which forced a temporary halt to remote learning. In 2022 the group claimed responsibility for a ransomware incident at Oklahoma City Indian Clinic that disabled pharmacy automatic refill and mail‑order services, asserting the theft of over three hundred fifty gigabytes of financial and health records despite the clinic’s denial of confirmed data exposure. That same year SunCrypt attacked Lüchinger + Schmid AG, a Migros subsidiary, stealing data and threatening public release to pressure the parent company into payment, although no ransom was ultimately transferred. These incidents demonstrate the group’s reliance on credential‑stealing malware, script‑based lateral movement, and data‑leak extortion to achieve financial objectives across multiple industries.
Incidents
Attributed incidents are available to members.
4 incidents