Crysis XTBL

First seen
2016-09-01 00:00:00
Malware type
ransomware
Profile updated
2026-07-07 16:10:04

Targeted industries: healthcare-and-pharmaceutical financial-services retail-and-hospitality manufacturing

Context

Crysis XTBL is a variant of ransomware that encrypts files on the victim's system and demands a ransom for the decryption key. It targets multiple industries and often spreads through phishing emails or exploit kits. Known for using the '.xtbl' file extension, it also attempts to delete shadow copies to prevent recovery.