Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Rancoz

Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered a Vice Society copycat, deployed against a small number of organizations using double extortion and linked to the same developer as the "Buddy" ransomware.

Victims
6
 
First Victim
2023-05-05
(est. attack date)
Discovery Date
2023-05-05
 
Last Seen
2023-09-03
 
Inactive Since
2yrs
more than
Avg Delay
N/A
attack→claim
Infostealer
0.0%
victims with domain
Countries
0
hit
Uptime
— avg (30d)
View Victims on World Map View Group Statistics

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Rancoz | Blog No 2026-04-28T07:21:29 ze677xuzard4lx4iul2yzf5ks4gqqzoulgj5u4n5n4bbbsxjbfr7eayd.onion

Target
Top 5 Activity Sectors
  • Manufacturing 3
  • Professional Services 1
  • Hospitality 1
  • Technology 1
Top 5 Countries

Heatmap

Ransom Notes (1)

YARA Rules (1)

Indicators of Compromise (IoCs) (1)
Email 1
Type IOC
Email rec_rans@aol.com

Victims (6)
Logo
Discovered: 2023-09-03 (2y ago)
Manufactures…
Logo
Discovered: 2023-09-03 (2y ago)
Legal Services industry…
Logo
Discovered: 2023-07-07 (3y ago)
Custom Heat Exchanger Manufacturer…
Logo
Discovered: 2023-06-14 (3y ago)
Construction industry…
Logo
Discovered: 2023-05-05 (3y ago)
Electrical Equipment Manufacturing…
Logo
Discovered: 2023-05-05 (3y ago)
Software and services company…