SunCrypt is a ransomware as a service (RaaS) operation that was first observed in October 2019 and became more well-known in mid-2020 . Although the ransomware has not been detected in many attacks recently, some researchers believe that it is still active, as its operators try to add new capabilities and features.

It is worth noting that SunCrypt ransomware was one of the first to use the triple extortion technique. This technique involves encrypting files, threatening to publish stolen data, and launching DDoS on victims who do not pay the ransom.
See also: Which ransomware encrypts data the fastest? (comparison of 10 variants)
The first version of this ransomware was written in GO, but after the release of the C and C++ versions in mid‑2020, the group became much more active, although not as active as other ransomware groups.
According to a report by Minerva Labs, however, there is now an updated version of the SunCrypt ransomware that includes new features.
SunCrypt ransomware: New features
The new capabilities of the SunCrypt 2022 variant appear to include process termination, service interruption, and wiping the machine to execute ransomware.
These features are not unknown to other ransomware strains, but for SunCrypt, they are very recent additions. According to Minerva Labs, the new version is likely still in an early stage of development.
The process termination includes processes with large resources that can hinder file encryption, such as WordPad (documents), SQLWriter (databases) and Outlook (email). Specifically, SunCrypt terminates the following processes before encryption begins:
- Ocssd.exe
- Dbsnmp.exe
- Synctime.exe
- Agntsvc.exe
- Isqlplussvc.exe
- Xfssvccon.exe
- Mydesktopservice.exe
- Ocautoupds.exe
- Encsvc.exe
- Firefox.exe
- Tbirdconfig.exe
- Mydesktopqos.exe
- Ocomm.exe
- dbeng50.exe
- sqbcoreservice.exe
- excel.exe
- infopath.exe
- msaccess.exe
- mspub.exe
- onenote.exe
- outlook.exe
- powerpnt.exe
- steam.exe
- thebat.exe
- thunderbird.exe
- visio.exe
- winword.exe
- wordpad.exe
- ssms.exe
- notepad/notepad++.exe
- fdhost.exe
- fdlauncher.exe
- launchpad.exe
- sqlceip.exe
- sqlwriter.exe
Regarding the wiping function, it is activated at the end of the encryption routine, using two API calls to delete all log files. After all log files are deleted, the ransomware is removed from the disk using cmd.exe with the following command: “cmd.exe /C ping 127.0.0.1 -n 10 > nul & del /f /q “path to the currently running process” > nul” .
See also: FBI: In 2021 ransomware groups struck 649 critical US infrastructures
One of the important old features retained in the newer version of SunCrypt ransomware is the use of I/O completion ports which allows for faster encryption through process threading.
It also appears that SunCrypt continues to encrypt both local volumes and network shares and still maintains an allowlist for the Windows directory, boot.ini, dll files, recycle bin, and other items that render a computer inoperable if they are encrypted.

Ransomware activity
According to statistics from ID Ransomware, which provides a good idea of ransomware activity, SunCrypt is still encrypting victims, but it appears to be seeing limited activity. At least for now.
See also: A man was caught spying on his girlfriend with an Apple Watch
However, the group may target high-profile companies and keep ransom negotiations private, without drawing the attention of law enforcement authorities and the media.
With the new release, the SunCrypt ransomware may become more active and dangerous.
Source: Bleeping Computer
