C77L
C77L is a ransomware operation and ransomware-as-a-service (RaaS) identified by F6. Reporting states it has been tied to at least 40 attacks against Russian and Belarusian enterprises since March 2025, and that the operation appears to be run out of Iran. No additional high-confidence technical details (e.g., initial access vectors, encryption behavior, extortion model, tooling, or specific indicators of compromise) are provided in the available content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Persistence
1 technique
Persistence
Impact
1 technique
Impact
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation targeting Russian and Belarusian enterprises, with initial access via weak passwords on exposed RDP/VPN services.
Ransomware operation targeting Russian and Belarusian enterprises; initial access reportedly via weak passwords on exposed RDP/VPN services and focused on Windows environments.
Ransomware-as-a-Service (RaaS) active since March (year not specified in the text) and used against at least 40 Russian and Belarusian organizations; initial access noted as unsecured VPN and RDP endpoints.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.