Inactive ransomware operator
← All groupsLorenz
78 victims indexed · first seen 6 years ago · last activity 2 years ago
At a glance
- Status
- inactive
- First seen
- 6 years ago
- Last activity
- 2 years ago
- Onion sites
- 2 known endpoints
- Primary sector
- Healthcare · 5 hits
About
References
10 linksExternal sources curated by the MISP threat-intel community.
- ransomlook.io/group/lorenz
- zdnet.com/article/lorenz-ransomware-attack-victims-can-now-retrieve-their-files-for-free-with-this-decryption-tool
- cybertalk.org/the-worst-outcomes-lorenz-ransomware-a-new-double-extortion-strategy
- arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/
- therecord.media/free-decrypter-available-for-lorenz-ransomware/
- twitter.com/AltShiftPrtScn/status/1423190900516302860?s=20
- bleepingcomputer.com/news/security/meet-lorenz-a-new-ransomware-gang-targeting-the-enterprise/
- cybereason.com/blog/cybereason-vs.-lorenz-ransomware
- tesorion.nl/en/posts/lorenz-ransomware-analysis-and-a-free-decryptor/
- tesorion.nl/en/posts/lorenz-ransomware-rebound-corruption-and-irrecoverable-files/
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
9 techniques · 7 tacticsTactics
Recent victims
Loading…
Onion infrastructure
2 known- http://lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion
- http://lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion/
Source
Updated 2 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
