CryptoLocker

First seen
2013-09-05 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 15:42:30

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality professional-services

Context

CryptoLocker is a notorious ransomware that emerged in 2013, encrypting users' files and demanding payment for the decryption key. It rapidly targeted various sectors for financial gain, employing sophisticated encryption techniques to pressure victims into compliance.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Cryptolocker (yara-rule)
  • MALPEDIA_Win_Cryptolocker_Auto (yara-rule)

Reports & references

  • secureworks.com — Gold Evergreen (report)
  • secureworks.com — Evolution Of The Gold Evergreen Threat Group (report)
  • Mandiant — Your Locker Of Information For Cryptolocker Decryption (report)
  • reaqta.com — Uncovering Ransomware Distribution Operation Part 2 (report)
  • CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
  • sites.temple.edu — Ci Rw Attacks (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
  • web.archive.org — Globalthreatintelreport (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cryptolocker (report)
  • secureworks.com — Gold Evergreen (report)
  • Microsoft — Human Operated Ransomware (report)
  • secureworks.com — Cryptolocker Ransomware (report)
  • justice.gov — Us Leads Multi National Action Against Gameover Zeus Botnet And Cryptolocker Ransomware (report)

External references