CryptoNar
- First seen
- 2023-08-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:42:45
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
When the CryptoNar, or Crypto Nar, Ransomware encrypts a victims files it will perform the encryption differently depending on the type of file being encrypted. If the targeted file has a .txt or .md extension, it will encrypt the entire file and append the .fully.cryptoNar extension to the encrypted file's name. All other files will only have the first 1,024 bytes encrypted and will have the .partially.cryptoNar extensions appended to the file's name.
Detection coverage
- 1 YARA rules
Detection rules
- TRELLIX_ARC_Cryptonar_Ransomware (yara-rule)
Related threat objects
- CryptoJoker (malware)
Reports & references
- bleepingcomputer.com — Cryptonar Ransomware Discovered And Quickly Decrypted (report)
- twitter.com — 1034492151541977088 (report)
- id-ransomware.blogspot.com — Cryptonar Ransomware (report)