Cryakl

Aliases: CryLock

First seen
2015-09-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 15:43:27

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector

Targeted regions: country_code:ru country_code:ua

Context

Cryakl, also known as CryLock, is a ransomware family that encrypts files on infected machines, demanding a ransom for decryption. It has primarily targeted the financial services, healthcare, and public sectors, particularly in Russia and Ukraine.

Related threat objects

Reports & references

  • Kaspersky — 86511 (report)
  • sensorstechforum.com — Fairytail Files Virus Cryakl Ransomware Remove Restore Data (report)
  • technologynews.tech — Cryakl Ransomware Virus (report)
  • zdnet.com — Cryakl Ransomware Decryption Keys Now Available For Free (report)
  • ke-la.com — The Ideal Ransomware Victim What Attackers Are Looking For (report)
  • bartblaze.blogspot.com — Vipasana Ransomware New Ransom On Block (report)
  • blog.checkpoint.com — Offline Ransomware Encrypts Your Data Without Cc Communication (report)
  • hackmag.com — Ransomware Russian Style (report)
  • Kaspersky — 104452 (report)
  • securelist.ru — 24070 (report)
  • twitter.com — 1217866089964679174 (report)
  • twitter.com — 1305197264332369920 (report)
  • twitter.com — 971164798376468481 (report)
  • elastic.co — Ten Process Injection Techniques Technical Survey Common And Trending Process (report)
  • sophos.com — Detailed Analysis (report)
  • telekom.com — Lockdata Auction 631300 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cryakl (report)
  • Palo Alto Unit 42 — Trigona Ransomware Update (report)

External references