crylock logo

crylock

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Cryakl
Ver en IntelTracker → APTTrail →
CryLock is a ransomware operation that emerged in April 2020 as a variant of the Cryakl ransomware family, also known as Fantomas. This group is primarily motivated by financial gain through cryptoviral extortion, demanding cryptocurrency payments for file decryption. A distinguishing feature of CryLock is its file renaming convention during encryption, where it appends a developer's email, a unique victim ID, and a randomized three-letter extension to affected files. The group has shown an evolution in its operational model, moving towards a semi-affiliate structure offering customizable options to partners. While primarily employing encryption, some instances suggest the group may also operate as a data broker, or adopt a double extortion model by exfiltrating sensitive data and threatening its public release.
Tecnicas MITRE
T1078, T1486, T1566.001, T1027, T1047

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Russia (1)

Paises objetivo (SOCRadar)

BelgiumBrazilGermanySpainUnited KingdomItalyPortugalUnited States

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingInformation ServicesFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOtherPublic Administration

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com