CryptoNar

First seen
2023-08-15 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:42:45

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

When the CryptoNar, or Crypto Nar, Ransomware encrypts a victims files it will perform the encryption differently depending on the type of file being encrypted. If the targeted file has a .txt or .md extension, it will encrypt the entire file and append the .fully.cryptoNar extension to the encrypted file's name. All other files will only have the first 1,024 bytes encrypted and will have the .partially.cryptoNar extensions appended to the file's name.

Detection coverage

  • 1 YARA rules

Detection rules

  • TRELLIX_ARC_Cryptonar_Ransomware (yara-rule)

Related threat objects

Reports & references

  • bleepingcomputer.com — Cryptonar Ransomware Discovered And Quickly Decrypted (report)
  • twitter.com — 1034492151541977088 (report)
  • id-ransomware.blogspot.com — Cryptonar Ransomware (report)

External references