Crypton Ransomware

Aliases: Nemesis, X3M

First seen
2017-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-06 12:57:11
Profile updated
2026-07-07 13:30:31

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Infostealer_Win_Nemesis_In_Memory (yara-rule)

Reports & references

  • id-ransomware.blogspot.co.il — Crypton Ransomware (report)
  • decrypter.emsisoft.com — Crypton (report)
  • bleepingcomputer.com — Crypton Ransomware Is Here And Its Not So Bad (report)
  • twitter.com — 829353444632825856 (report)
  • ransomlook.io — Nemesis (report)

External references