The operators of the RansomExx ransomware have become the latest to develop a new variant fully rewritten in the Rust programming language, following other strains like BlackCat, Hive, and Luna.
The most recent version, dubbed RansomExx2, was created by the threat actor known as Hive0091 (also known as DefrayX). It is primarily intended to run on Linux, though a Windows version is anticipated in the future. RansomExx, also referred to as Defray777 and Ransom X, is a family of ransomware that has been in circulation since 2018.
Since then, it has been connected to several attacks against manufacturers, government organizations, and other well-known companies like Embraer and GIGABYTE.