ThunderX ransomware changed its name to "Ranzy Locker" and last week launched the data leak site "Ranzy Leak", where it shames victims who refuse to pay the ransom demanded by the ransomware operators.
ThunderX is a ransomware operation that began operating in late August. Shortly after its appearance on the threat landscape, flaws in the ransomware were discovered that allowed Tesorion to release a free decryptor. The ransomware operators quickly patched the flaws and released a new version of the ransomware called “Ranzy Locker.”

Despite the fact that the hackers changed the name of the ransomware they developed, strings associated with a PDB debug file in the ransomware executables indicate that it is the same as ThunderX.
MalwareHunterteam has discovered a ransomware sample that shows some clues about how the ransomware works. When launched, Ranzy Locker first cleans up “Shadow Volume Copies”so that victims cannot use it to recover encrypted files. When encrypting files, the ransomware uses a Windows API called “Windows Restart Manager,” which terminates Windows processes or services that are keeping a file open and prevents it from being encrypted. For each encrypted file, the ransomware appends the new .ranzy to the file name. For example, a file named 1.docis encrypted and renamed to 1.doc.ranzy.

In each traversed folder, the ransomware creates a ransom note called “readme.txt”that contains information about what happened to data , a warning that their data has been stolen, and a link that directs the victim to a Tor site where they can negotiate with the hackers who attacked them. In previous versions of ThunderX ransomware, its operators communicated with their victims via email instead of using a dedicated Tor site.
When a victim visits the Tor payment site, they are presented with a message that reads “Locked by Ranzy Locker” as well as a live chat screen to start negotiations with the hackers. As part of this “service,” the ransomware operators allow victims to decrypt three files for free to prove they can do this.

As BleepingComputer reports, many ransomware gangs use a double-extortion attack method, in which they steal unencrypted files from a victim before encrypting devices located on a corporate network.
Using this attack method, hackers push their victims to pay a ransom in two ways: they claim that if the victims pay the required ransom, a) they will have their files returned and b) their data will not be leaked.
Notably, the Tor onion URL used by the data leak site “Ranzy Leak” is the same as the one previously used by the Ako ransomware. Using the same URL as Ako could mean that both gangs merged to form Ranzy Locker, or that they are working together similarly to the Maze cartel.
