CryptFIle2
Aliases: Lesli
- First seen
- 2017-05-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-06-24 07:45:04
- Profile updated
- 2026-07-07 13:33:20
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:us country_code:uk country_code:de
Context
CryptFIle2, also known as Lesli, is a ransomware family designed to encrypt victims' files and demand ransom payments. It has been observed targeting multiple industries and has affected systems primarily in the US, UK, and Germany.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Qnapcrypt (yara-rule)
Reports & references
- proofpoint.com — Ransomware Explosion Continues Cryptflle2 Brlock Mm Locker Discovered (report)
- id-ransomware.blogspot.com — Cryptfile2 Ransomware Rsa Email (report)