crynox

First seen
2023-09-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:52:36

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications

Context

Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to encrypted files and drops a ransom note (read_it.txt) instructing victims to contact [email protected]. It seems to use RSA-4096 and AES for encryption and may change desktop wallpaper, but there's no evidence of double-extortion or leak site operation. Distribution methods cited include phishing, pirated software, and malicious websites.

Reports & references

  • pcrisk.com — 27862 Ciphbit Ransomware (report)
  • ransomlook.io — Crynox (report)
  • sensorstechforum.com — Crynox Ransomware (report)
  • pcrisk.com — 31766 Crynox Ransomware (report)
  • cyclonis.com — Remove Crynox Ransomware (report)

External references