Crylock
Aliases: Cryakl
- First seen
- 2019-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:38:39
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical
Targeted regions: country_code:ru country_code:ua country_code:us
Context
Crylock, also known as Cryakl, is a ransomware malware family that encrypts users' files and demands a ransom for the decryption key. It has targeted various sectors including financial services and healthcare, with notable activity in Eastern Europe and the United States.
Detection coverage
- 4 YARA rules
Detection rules
- ARKBIRD_SOLG_RAN_Crylock_Oct_2020_1 (yara-rule)
- TELEKOM_SECURITY_Crylock_Binary (yara-rule)
- TELEKOM_SECURITY_Crylock_Hta (yara-rule)
- DITEKSHEN_MALWARE_Win_Crylock (yara-rule)
Reports & references
- Kaspersky — 86511 (report)
- ke-la.com — The Ideal Ransomware Victim What Attackers Are Looking For (report)
- bartblaze.blogspot.com — Vipasana Ransomware New Ransom On Block (report)
- blog.checkpoint.com — Offline Ransomware Encrypts Your Data Without Cc Communication (report)
- hackmag.com — Ransomware Russian Style (report)
- Kaspersky — 104452 (report)
- securelist.ru — 24070 (report)
- twitter.com — 1217866089964679174 (report)
- twitter.com — 1305197264332369920 (report)
- twitter.com — 971164798376468481 (report)
- elastic.co — Ten Process Injection Techniques Technical Survey Common And Trending Process (report)
- sophos.com — Detailed Analysis (report)
- telekom.com — Lockdata Auction 631300 (report)
- ransomlook.io — Crylock (report)
- pcrisk.com — 16814 Crylock Ransomware (report)
- Trend Micro — Ransom.Win32.Crylock.H (report)
- alartindex.com (report)
- singleton.com — Describing Crylock Ransomware (report)
- watchguard.com (report)