Threat Actor Profile
Description
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.
Confidence Score
Tags
First Seen
Unknown
Last Updated
Unknown
Active Status
ActiveCreated
April 29, 2026
Indicators of Compromise
Loading IOCs…
IOC KQL for Sentinel
STIX Data
{'added_date': None,
'client': '2003264@sit.singaporetech.edu.sg',
'description': 'Tesorion describes Lorenz as a ransomware with design and '
'implementation flaws, leading to impossible decryption with '
'tools provided by the attackers. A free decryptor for 2021 '
'versions was made available via the NoMoreRansom initiative. '
'A new version of the malware was discovered in March 2022, '
'for which again was provided a free decryptor, while the '
'ransomware operators are not able to provide tools to decrypt '
'affected files.\n',
'firstseen': '2020-01-12T00:00:00+00:00',
'group': 'lorenz',
'has_negotiations': False,
'has_ransomnote': True,
'lastseen': '2023-12-01T00:00:00+00:00',
'locations': [{'available': False,
'fqdn': 'lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion',
'slug': 'http://lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion',
'title': 'Lorenz',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 2,
'tiaras_metadata': {'has_negotiations': False,
'has_ransomnote': True,
'locations': [{'available': False,
'fqdn': 'lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion',
'slug': 'http://lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion',
'title': 'Lorenz',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 2,
'ransomware_live_group': 'lorenz',
'tools': {},
'url': 'https://www.ransomware.live/group/lorenz',
'victims': 78,
'vulnerabilities': []},
'tiaras_source': 'ransomware.live',
'tools': {},
'ttps': [],
'url': 'https://www.ransomware.live/group/lorenz',
'victims': 78,
'vulnerabilities': []}