TeslaCrypt
Aliases: cryptesla
- First seen
- 2015-02-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-19 03:21:10
- Profile updated
- 2026-07-07 14:33:36
Targeted industries: media-and-entertainment technology-and-telecommunications
Context
According to Kaspersky, detected in February 2015, the new ransomware Trojan gained immediate notoriety as a menace to computer gamers. Amongst other types of target files, it tries to infect typical gaming files: game saves, user profiles, recoded replays etc. That said, TeslaCrypt does not encrypt files that are larger than 268 MB. Recently,
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Teslacrypt_Auto (yara-rule)
Reports & references
- community.riskiq.com — 30F22A00 (report)
- Trend Micro — New In Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Teslacrypt (report)
- blogs.cisco.com — Teslacrypt (report)
- blog.checkpoint.com — Tesla Crypt Whitepaper V3 (report)
- Trend Micro — 1113900 Emerging Threat On Ransom Cryptesla (report)
- ESET — Nemucod Malware Spreads Ransomware Teslacrypt Around World (report)
- Kaspersky — 71371 (report)
- blog.christophetd.fr — Malware Analysis Lab With Virtualbox Inetsim And Burp (report)
- blog.malwarebytes.com — Teslacrypt Spam Campaign Unpaid Issue (report)
- endgame.com — Your Package Has Been Successfully Encrypted Teslacrypt 41A And Malware Attack (report)
- researchcenter.paloaltonetworks.com — Latest Teslacrypt Ransomware Borrows Code From Carberp Trojan (report)