Crypter
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 13:34:06
Context
Ransomware Does not actually encrypt the files, but simply renames them
Detection coverage
- 9 YARA rules
Detection rules
- RUSSIANPANDA_Truecrypt_Crypter (yara-rule)
- RUSSIANPANDA_Win_Mal_Fatmalloc (yara-rule)
- COD3NYM_MAL_NET_Limecrypter_Runpe_Jan24 (yara-rule)
- DITEKSHEN_INDICATOR_RTF_Ancalog_Exploit_Builder_Document (yara-rule)
- SEKOIA_Crypter_Win_Dotrunpex (yara-rule)
- SIGNATURE_BASE_MAL_Gozicrypter_Dec20_1 (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Crypter_Runtime_AV_S_Bypass (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Lime_Crypter (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Conticrypter (yara-rule)
Reports & references
- twitter.com — 802554159564062722 (report)