Cryptowall
- First seen
- 2014-04-01 00:00:00
- Malware type
- ransomware, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:36:14
- Profile updated
- 2026-07-07 13:44:27
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality education-and-nonprofits government-and-public-sector
Context
CryptoWall is a ransomware, is usually spread by spam and phishing emails, malicious ads, hacked websites, or other malware and uses a Trojan horse to deliver the malicious payload.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Cryptowall_Auto (yara-rule)
Reports & references
- sites.temple.edu — Ci Rw Attacks (report)
- ESET — Eset Threat Report Q22020 (report)
- gdatasoftware.com — 31666 Ransomware Identification For The Judicious Analyst (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cryptowall (report)
- ryancor.medium.com — Genetic Analysis Of Cryptowall Ransomware 843F86055C7F (report)