CryptoLocker
- First seen
- 2013-09-05 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 15:42:30
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality professional-services
Context
CryptoLocker is a notorious ransomware that emerged in 2013, encrypting users' files and demanding payment for the decryption key. It rapidly targeted various sectors for financial gain, employing sophisticated encryption techniques to pressure victims into compliance.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Cryptolocker (yara-rule)
- MALPEDIA_Win_Cryptolocker_Auto (yara-rule)
Reports & references
- secureworks.com — Gold Evergreen (report)
- secureworks.com — Evolution Of The Gold Evergreen Threat Group (report)
- Mandiant — Your Locker Of Information For Cryptolocker Decryption (report)
- reaqta.com — Uncovering Ransomware Distribution Operation Part 2 (report)
- CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
- sites.temple.edu — Ci Rw Attacks (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
- web.archive.org — Globalthreatintelreport (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cryptolocker (report)
- secureworks.com — Gold Evergreen (report)
- Microsoft — Human Operated Ransomware (report)
- secureworks.com — Cryptolocker Ransomware (report)
- justice.gov — Us Leads Multi National Action Against Gameover Zeus Botnet And Cryptolocker Ransomware (report)