Uptime Hamster: 12d 20h 11mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza rancoz

rancoz

2 incidentes 1 paises 1 sectores ransomware EE Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Rancoz is a ransomware group that first emerged in November 2022, operating with a financial motivation through double extortion tactics. The group distinguishes itself by leveraging a combination of NTRUEncrypt, a post-quantum algorithm, and ChaCha20-Poly1305 for its encryption processes. Rancoz primarily targets virtualization platforms such as Proxmox to maximize operational disruption by encrypting multiple virtual machines simultaneously. Although sharing code similarities with Vice Society ransomware, no direct link has been established; however, Rancoz is assessed to be from the same developer as Buddy ransomware.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownze677xuzard4lx4iul2yzf5ks4gqqzoulgj5u4n5n4bbbsxjbfr7eayd.onionrancoz
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: rancoz
Tecnicas MITRE
T1059.001, T1071.001, T1486, T1027
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

CanadaFranceIndiaLithuaniaUnited States

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsSoftware PublishersEnterprises & HoldingManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationEducational ServicesEnergy & Utilities Insurance

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com