Crypton Ransomware
Aliases: Nemesis, X3M
- First seen
- 2017-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-06 12:57:11
- Profile updated
- 2026-07-07 13:30:31
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Infostealer_Win_Nemesis_In_Memory (yara-rule)
Reports & references
- id-ransomware.blogspot.co.il — Crypton Ransomware (report)
- decrypter.emsisoft.com — Crypton (report)
- bleepingcomputer.com — Crypton Ransomware Is Here And Its Not So Bad (report)
- twitter.com — 829353444632825856 (report)
- ransomlook.io — Nemesis (report)