CryptFIle2

Aliases: Lesli

First seen
2017-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-06-24 07:45:04
Profile updated
2026-07-07 13:33:20

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:us country_code:uk country_code:de

Context

CryptFIle2, also known as Lesli, is a ransomware family designed to encrypt victims' files and demand ransom payments. It has been observed targeting multiple industries and has affected systems primarily in the US, UK, and Germany.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Qnapcrypt (yara-rule)

Reports & references

  • proofpoint.com — Ransomware Explosion Continues Cryptflle2 Brlock Mm Locker Discovered (report)
  • id-ransomware.blogspot.com — Cryptfile2 Ransomware Rsa Email (report)

External references