Free tools Windows power users keep installed
One-click scans. No signup required.
The FBI’s October 25, 2021, Ranzy Locker flash describes historical indicators of compromise (IOCs) that defenders can use to guide a hunt—not as stand-alone proof of infection or as a current threat tally. It reports that more than 30 U.S. businesses had been compromised by July 2021, and outlines reported access routes, Windows encryption behavior, and clues such as new “felix” accounts and the .ranzy extension.
What the FBI’s Ranzy Locker flash covers
The FBI published “Indicators of Compromise Associated with Ranzy Locker Ransomware” on October 25, 2021, in coordination with DHS/CISA. The flash says the FBI first identified the ransomware in late 2020 and counted more than 30 compromised U.S. businesses as of July 2021. That is a historical count, not a present-day victim total.
Reported victims included organizations in information technology and transportation; construction, within critical manufacturing; and academia, within government facilities. The advisory is useful for understanding the activity and shaping retrospective or behavior-based hunts, but it does not establish current prevalence or whether any particular indicator remains valid.
How Ranzy Locker reportedly gained access
The FBI described three reported access vectors. The reports came from different victims; the flash does not establish that every incident involved all three.
#1 Best Overall
| Reported access vector | What the FBI said | Defensive focus |
|---|---|---|
| RDP credential brute force | A majority of victims reported that attackers brute-forced Remote Desktop Protocol (RDP) credentials. | Review remote-access logs, limit exposure, disable unused RDP, and require multifactor authentication. |
| Microsoft Exchange Server vulnerabilities | Some more recent victims reported exploitation of known Exchange Server vulnerabilities. | Check patch status and investigate suspicious Exchange activity in the context of other telemetry. |
| Phishing | Some more recent victims reported phishing as an access route. | Investigate suspicious messages and account activity alongside endpoint and identity evidence. |
What the ransomware did after access
The FBI said Ranzy Locker encrypted files on compromised Windows hosts, including servers and virtual machines, as well as attached network shares. It left a ransom note in directories where encryption occurred and demanded payment for a decryption tool. In some cases, actors also demanded payment to prevent the leak of stolen information—a double-extortion tactic.
The advisory says the actors sought important files, including customer information, personally identifiable information (PII), and financial records, for exfiltration. A response should therefore consider possible data theft as well as encrypted systems; restoration alone may not address exposure concerns.
Rank #2
Ranzy Locker indicators of compromise: what to look for
The accessible reproduction of the FBI flash describes the following clues. The FBI characterized its IOCs as “likely associated” with Ranzy Locker activity, and cautioned that context matters. An artifact is a lead for investigation, not a verdict by itself.
| Indicator or behavior | What was reported | How to interpret it |
|---|---|---|
New account named felix |
Observed on at least three victims; accounts could be created on domain controllers, servers, workstations, or Active Directory. | Check account creation time, ownership, authorization, logon activity, and related changes. A matching name without corroborating evidence is not proof of Ranzy Locker. |
| Ransom-note key | Described as a base64-encoded string whose decoded fields include an extension, a network flag, a subID, and a language. | Preserve the note and associated files for analysis. Do not treat a matching format alone as conclusive attribution. |
.ranzy extension |
Described as typical for Ranzy Locker 1.1. | Use it to identify files for triage, then verify against host, account, and network evidence. A filename extension can be changed or reused. |
| Executable characteristics | The subID was described as the ransomware executable’s filename stem; the executable was characterized as a 32-bit portable executable requiring administrator credentials to run. | Investigate file provenance, process execution, privileges, and timing rather than relying on the filename stem alone. |
The FBI’s reproduced warning notes that filenames and IP addresses can be ephemeral or nondeterministic and may not indicate compromise on their own. Exact hashes and network IOC values are not reproduced here; consult official FBI/CISA materials and validate any indicators against current telemetry before operational use.
Rank #3
How defenders can use the indicators safely
- Preserve evidence before making changes. Record suspicious account details, ransom notes, affected paths, timestamps, and relevant endpoint, identity, and remote-access logs. Follow your incident-response procedures so containment does not destroy evidence.
- Correlate clues across systems. Investigate a new account or
.ranzyfile alongside authentication events, process activity, affected shares, and signs of data staging or transfer. A single artifact should not determine incident scope or attribution. - Scope for both encryption and possible theft. Identify affected Windows hosts, servers, virtual machines, and attached shares. Consider whether customer, PII, or financial information may have been accessed or exfiltrated.
- Contain access paths. Limit or disable unused RDP, review remote-access logs, patch operating systems and software—including Exchange where applicable—and use multifactor authentication. Apply least privilege and review domain controllers, servers, workstations, and Active Directory for unrecognized accounts.
- Protect recovery. Maintain regular, password-protected offline backups that cannot be changed or deleted from systems holding the originals. Segment networks, keep security software current, and test that backups completed and can be restored.
Recovery, ransom, and reporting
The FBI’s ransomware guidance recommends keeping operating systems, software, and applications current; automatically updating anti-malware; backing up data and checking backup completion; keeping backups disconnected from protected systems; and maintaining an organizational continuity plan.
The FBI states, “The FBI does not support paying a ransom in response to a ransomware attack.” It also warns that payment does not guarantee data will be returned. Organizations facing an incident should use their established response and legal processes and evaluate recovery and data-exposure issues separately.
Rank #4
For reporting, the FBI directs ransomware victims to a local FBI field office or the Internet Crime Complaint Center (IC3). Use the current official FBI reporting pages to confirm the appropriate route.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

