Frequently Asked Questions

RansomEXX Threat Details

What is RansomEXX and what makes it notable among ransomware variants?

RansomEXX is a ransomware strain linked to the Gold Dupont threat group, active since 2018. It is notable for having both Windows and Linux variants—the Linux version, discovered in late 2020, was the first time a major Windows ransomware expanded to target Linux systems. RansomEXX attacks are highly targeted, with the victim's name hardcoded into the binary, and often use trojanized legitimate tools to evade detection and deploy payloads quickly. Note: Detailed limitations of RansomEXX detection are not publicly documented; ask sales for specifics.

Who is the Gold Dupont group and how are they connected to RansomEXX?

The Gold Dupont group is a financially motivated cybercriminal organization active since 2018. They are known for using RansomEXX (also called Defray777), Cobalt Strike, Metasploit, and Vatet Loader in their campaigns. Their attacks often involve the use of trojanized legitimate tools and are tailored to specific victims, as evidenced by hardcoded target names in RansomEXX binaries. Note: Gold Dupont's full range of capabilities may extend beyond RansomEXX; consult threat intelligence sources for the latest details.

How does RansomEXX target organizations and what tools are used in its campaigns?

RansomEXX campaigns typically involve the use of malware such as Vatet Loader, PyXie RAT, TrickBot, and post-intrusion tools like Cobalt Strike. The group often uses trojanized legitimate tools to deploy ransomware payloads quickly and evade detection. A unique aspect is the hardcoding of the target's name in the binary, indicating a high degree of preparation and victim profiling. Note: Not all organizations may be equally targeted; high-value infrastructure is often at greater risk.

Ransomware & Exposure Management

What is ransomware and where can I learn more about it?

Ransomware is a type of malicious software that encrypts a victim’s files and demands a ransom for their restoration. For a comprehensive overview, visit Cymulate's ransomware glossary entry. Note: Ransomware tactics and variants evolve rapidly; always consult up-to-date sources.

What is Ransomware-as-a-Service (RaaS) and how does it impact organizations?

Ransomware-as-a-Service (RaaS) is a model where cybercriminals sell ransomware kits on the dark web, enabling even non-technical actors to launch attacks. Prices can be as low as USD 39 for variants like Stampado, which includes a lifetime license. This model expands the reach of ransomware threats. Learn more in Cymulate's blog post on RaaS. Note: The accessibility of RaaS increases the likelihood of opportunistic attacks.

What are the key statistics highlighting the need for exposure management against ransomware?

Recent statistics show that 67% of companies paid a ransom in the last year, 47% lost potential customers post-breach, only 2% have firm-wide cyber resilience, and the average recovery time after a cyber event is over 6 days. (Sources: Cohesity, PWC, Cyber Magazine). Note: These figures highlight the importance of proactive exposure management, but individual results may vary.

Where can I find resources on exposure management and ransomware resilience?

Cymulate offers an e-book: A Practical Guide to Exposure Management and a blog post: 7 Essential Steps to Becoming Ransomware Resilient. These resources provide practical steps and industry insights for reducing ransomware risk. Note: These guides are general and may need adaptation for your specific environment.

Cymulate Platform Capabilities & Ransomware Defense

How does Cymulate help organizations defend against ransomware threats like RansomEXX?

Cymulate provides continuous threat exposure management, automated threat validation, and a comprehensive threat library to simulate and assess defenses against ransomware variants, including RansomEXX. The platform's immediate threats module is updated rapidly to reflect new attacks, enabling organizations to quickly assess risk and implement remediation. Note: Cymulate's effectiveness depends on proper configuration and ongoing use; it may not prevent all attacks.

Which types of threats can Cymulate validate?

Cymulate can validate threats such as malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios for comprehensive security validation. Note: Some highly targeted or novel threats may require custom simulation development.

What is the immediate threats module in Cymulate and how does it benefit users?

The immediate threats module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. A Penetration Tester noted: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Note: The speed of updates depends on threat intelligence feeds and platform configuration.

Technical Documentation & Resources

Where can I find technical documentation about Cymulate's ransomware and threat validation capabilities?

Cymulate provides technical documentation and data sheets, including the Threat Studio data sheet and the Detection Engineering Automation Guide. For a comprehensive collection, visit the Cymulate resource hub. Note: Some resources may require registration or additional access permissions.

Competition & Comparison

How does Cymulate compare to AttackIQ for ransomware and exposure validation?

Cymulate offers AI-driven, actionable remediation guidance, a daily-updated attack scenario library, and an AI Copilot for converting threat intelligence into automated tests. AttackIQ is a direct competitor in breach and attack simulation. Cymulate is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights for Adversarial Exposure Validation. Choose Cymulate if you need rapid, AI-powered validation and remediation; choose AttackIQ if you require a different approach to scenario customization. Note: AttackIQ may offer unique integrations or workflows not present in Cymulate.

Customer Success & Case Studies

What business impact have customers seen from using Cymulate for ransomware defense?

Organizations using Cymulate have reported an average 30% increase in threat prevention, 90% improvement in threat detection, and a 52% reduction in critical exposures. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months (case study). Note: Results may vary based on organization size, configuration, and threat landscape.

Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Ransomware Spotlight RansomEXX

May 22, 2022

It has both a Windows and Linux variant. RansomEXX's Linux version, discovered in late 2020, marked the first known time a major Windows ransomware variant expanded to Linux. This move allows modern ransomware variants to target core infrastructure that are often running on Linux. Linked to the threat group Gold Dupont. The threat group has been active since 2018. They are a financially motivated cybercriminal group with a main arsenal that includes RansomEXX or Defray777, Cobalt Strike, Metasploit, and Vatet Loader. Uses trojanized legitimate tools. RansomEXX campaigns, as typical of Gold Dupont attacks, involve malware like Vatet Loader, PyXie RAT, TrickBot, and post-intrusion tools like Cobalt Strike as part of their arsenal. The use of trojanized legitimate tools is common among modern ransomware variants, allowing them to deploy payloads faster while avoiding detection. Hardcoded name of the target in its binary. One of the key indicators of RansomEXX's targeted nature is how it has its target's name hardcoded in its binary. It demonstrates how RansomEXX attacks involve a certain amount of preparation and are tailored to their chosen victim's profile.