Crylock

Aliases: Cryakl

First seen
2019-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:38:39

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical

Targeted regions: country_code:ru country_code:ua country_code:us

Context

Crylock, also known as Cryakl, is a ransomware malware family that encrypts users' files and demands a ransom for the decryption key. It has targeted various sectors including financial services and healthcare, with notable activity in Eastern Europe and the United States.

Detection coverage

  • 4 YARA rules

Detection rules

  • ARKBIRD_SOLG_RAN_Crylock_Oct_2020_1 (yara-rule)
  • TELEKOM_SECURITY_Crylock_Binary (yara-rule)
  • TELEKOM_SECURITY_Crylock_Hta (yara-rule)
  • DITEKSHEN_MALWARE_Win_Crylock (yara-rule)

Reports & references

  • Kaspersky — 86511 (report)
  • ke-la.com — The Ideal Ransomware Victim What Attackers Are Looking For (report)
  • bartblaze.blogspot.com — Vipasana Ransomware New Ransom On Block (report)
  • blog.checkpoint.com — Offline Ransomware Encrypts Your Data Without Cc Communication (report)
  • hackmag.com — Ransomware Russian Style (report)
  • Kaspersky — 104452 (report)
  • securelist.ru — 24070 (report)
  • twitter.com — 1217866089964679174 (report)
  • twitter.com — 1305197264332369920 (report)
  • twitter.com — 971164798376468481 (report)
  • elastic.co — Ten Process Injection Techniques Technical Survey Common And Trending Process (report)
  • sophos.com — Detailed Analysis (report)
  • telekom.com — Lockdata Auction 631300 (report)
  • ransomlook.io — Crylock (report)
  • pcrisk.com — 16814 Crylock Ransomware (report)
  • Trend Micro — Ransom.Win32.Crylock.H (report)
  • alartindex.com (report)
  • singleton.com — Describing Crylock Ransomware (report)
  • watchguard.com (report)

External references