Skip to content

CryptoLocker

CryptoLocker is an early and highly influential Windows ransomware family first observed in 2013 and widely regarded as one of the first modern large-scale file-encrypting ransomware operations.

Profile source: Mallory opens in a new tab

CryptoLocker

Family profile

CryptoLocker is an early and highly influential Windows ransomware family first observed in 2013 and widely regarded as one of the first modern large-scale file-encrypting ransomware operations. Unlike earlier locker-style threats that primarily blocked access to the desktop, CryptoLocker encrypted victim files and demanded payment for decryption, helping establish the modern ransomware model.

CryptoLocker was distributed initially through spam campaigns carrying malicious attachments and later at scale through the Upatre downloader, the Gameover Zeus ecosystem, and the Cutwail botnet. Additional delivery through exploit-kit activity, including Blackhole and Magnitude, has also been reported. After execution, the malware established persistence in the user profile and configured autorun behavior to survive reboots. It then contacted command-and-control infrastructure using both hard-coded destinations and a domain generation algorithm.

Once active, CryptoLocker enumerated local drives, network shares, and later removable media, and encrypted a broad range of business and personal file types using strong cryptography implemented through Microsoft CryptoAPI. Reported analyses describe per-file symmetric encryption protected by attacker-controlled asymmetric keys, which made recovery without the corresponding private key impractical. The malware typically remained silent until encryption had completed, then presented a ransom interface with a payment deadline. Operators later added a decryption service for victims who missed the initial deadline.

CryptoLocker is closely associated with the Gameover Zeus criminal operation and has been linked in public reporting to the broader Russian-speaking cybercrime ecosystem around that botnet. It caused substantial global impact, with hundreds of thousands of infections reported during its active period and especially heavy victimization in English-speaking countries, including the United States. Its combination of resilient distribution, effective monetization, and strong encryption made it a defining ransomware threat and a template for many later families.

Capabilities

  • Exfiltration
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 13, 2026
Last activity
Sep 18, 2026
Feed role
C2 / Distribution
Host form
3 IP / 2 hostnames

Leading locations

  • NL2
  • US2
  • CA1

Leading providers

  • Omegatech LTD2
  • Google LLC1
  • SECURED SERVERS LLC1
  • Team Internet AG1

Infrastructure traits

  • Hosting 5

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Evgeniy Bogachev

Individual operators often dropped other malware β€’ CryptoLocker – first in-house development, destructive

MITRE ATT&CK

CryptoLocker in ATT&CK

25 distinct techniques

Reporting

Research mentioning CryptoLocker

Feb 18
Paloalto Researchcenter Historic

New Android Trojan β€œXbot” Phishes Credit Cards and Bank Accounts, Encrypts Devices for Ransom

Security researchers reported that the Android malware family Xbot evolved from a stealthy SMS-focused trojan into a broader banking and ransomware threat distributed through third-party app markets rather than Google Play. The malware masqueraded as trusted apps including Google Play, Opera Browser, Android Market, and Minecraft, then hid its launcher icon after installation to avoid detection. Early variants primarily targeted users in Russia and Eastern Europe, monitoring incoming SMS messages for selected keywords, exfiltrating messages to command-and-control infrastructure, sending premium-rate texts, downloading additional APKs, and persisting across reboots. Later analysis found Xbot embedded in 22 malicious apps and expanded to phishing Google Play payment details and login credentials for multiple banking apps, including major Australian banks and at least one Russian bank. The trojan used activity hijacking and WebView overlays to present fake login and card-entry screens, stole SMS messages and contacts, abused device administrator privileges, and accepted remote commands from its operators. Researchers also found ransomware functions that could lock the device, set a password, encrypt files on external storage with a simple XOR routine, and demand a $100 PayPal My Cash Card payment, while added obfuscation and dormant call-recording code indicated active ongoing development.

Dec 16
Eset Welivesecurity

Nemucod malware spreads ransomware Teslacrypt

TeslaCrypt emerged as a fast-moving ransomware family that encrypted both common user documents and game-related files, including saved games and Steam-related data, expanding its impact to PC gamers. Initial infections were linked to malicious email attachments and exploit kits such as Angler, which abused browser and plugin flaws including Adobe Flash CVE-2015-0311; later distribution was also tied to Sweet Orange and Nuclear via compromised websites. The malware deleted Volume Shadow Copies, contacted command-and-control infrastructure, and used ransom notes and recovery files to pressure victims into paying in Bitcoin. Later TeslaCrypt variants significantly hardened their cryptography and extortion workflow. Researchers reported that early versions falsely claimed to use RSA-2048 while actually relying on AES-CBC-256, with key material stored locally in files such as key.dat, allowing decryption in some cases and enabling Cisco Talos to release a recovery utility when the necessary keys were present. TeslaCrypt 2.0, however, adopted a stronger design using ECDH over secp256k1 with AES-256-CBC, moved key-related data into the Windows registry, generated unique Bitcoin addresses per victim, appended the .zzz extension to encrypted files, and replaced its interface with an HTML ransom page modeled on CryptoWall, making recovery without attacker-controlled key material far more difficult.

Oct 9
Paloalto Researchcenter Historic

Latest TeslaCrypt Ransomware Borrows Code From Carberp Trojan

Jul 18
Securelist

TeslaCrypt 2.0 disguised as CryptoWall | Securelist

Apr 27
Cisco Talos

Threat Spotlight: TeslaCrypt - Decrypt It Yourself - Cisco Blogs

Feb 17
Avast

Angry Android hacker hides Xbot malware in popular application icons

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.