Virus-Encoder
Aliases: CrySiS
- First seen
- 2016-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-20 02:49:36
- Profile updated
- 2026-07-07 13:40:42
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications
Context
Virus-Encoder, also known as CrySiS, is a family of ransomware targeting various industries globally by encrypting files and demanding ransom payment in cryptocurrency. It is known for spreading through phishing emails and exploiting unpatched systems.
Related threat objects
- Hunt (malware)
Reports & references
- ESET — New Decryption Tool Crysis Ransomware (report)
- media.kaspersky.com — Rakhnidecryptor.Zip (report)
- nyxbone.com — Virus Encoder (report)
- Trend Micro — Crysis Targeting Businesses In Australia New Zealand Via Brute Forced Rdps (report)
- ransomlook.io — Crysis (report)
- bleepingcomputer.com — Crysis Ransomware Master Decryption Keys Released (report)
- Trend Micro — Crysis Ransomware Distributed Through Remote Desktop Services (report)
- Kaspersky — 78775 (report)
- nomoreransom.org — Decryption Tools (report)