Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 3 hostnames
CryptoLocker is a Windows-based ransomware family first seen in September 2013 that encrypts victim files using strong public-key cryptography and demands payment for decryption, typically within a 72- to 96-hour deadline.
Profile source: Mallory opens in a new tabCryptoLocker
CryptoLocker is a Windows-based ransomware family first seen in September 2013 that encrypts victim files using strong public-key cryptography and demands payment for decryption, typically within a 72- to 96-hour deadline. The malware is described as using RSA-2048 together with AES, retrieving a public key from command-and-control infrastructure and keeping the private decryption key off the victim system. It targets valuable user and business data including Microsoft Office documents, photos, MP3 files, databases, certificates, archives, and other common file types on local drives and mapped network drives; some reporting also notes mounted backups can be encrypted. CryptoLocker commonly arrives via phishing and spam campaigns, including ZIP attachments containing executables disguised as PDF files, and was also distributed through watering-hole attacks and by the Gameover Zeus botnet/Zbot infections. It persists from randomly named executables in %AppData% or %LocalAppData% using Run/RunOnce registry entries, records encrypted files in the registry, and attempts to delete Shadow Volume Copies via vssadmin. Payment methods mentioned in the content include Bitcoin, MoneyPak, prepaid cards, Ukash, and cashU, with ransom amounts commonly cited around $100 to $300, though some victims reportedly paid more. The malware was heavily associated with Gameover Zeus and the criminal enterprise tied by U.S. authorities to Evgeniy Mikhailovich Bogachev; DOJ and related reporting state GOZ was a primary vehicle for seeding CryptoLocker infections. Reported impact figures in the content include more than 234,000 infected computers, including over 117,000 in the United States, and more than $27 million in ransom payments in its first two months online. Targeting was global, with the United States specifically noted as heavily affected and business users frequently impacted; examples include an insurance company in Pittsburgh and a Massachusetts police department. Law-enforcement and private-sector disruption during Operation Tovar/Gameover in June 2014 seized or neutralized infrastructure associated with CryptoLocker, after which the original CryptoLocker distribution network was disabled. Notable indicators and artifacts directly mentioned in the content include registry paths such as HKEY_CURRENT_USER\Software\CryptoLocker\Files and HKEY_CURRENT_USER\Software\CryptoLocker_0388\Files, autostart entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, execution from %AppData% or %LocalAppData%, use of DGA-generated domains, and the command to delete shadow copies: vssadmin Delete Shadows /All /Quiet.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 c322fa3e02a79ecead674bc4a8e67b71d14632427f8dc9a380b0f588941bbf1a f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 84b8ec2f3b29a10f88d21fc7617cdfecac1c2c76303086b41471beb5f563f65c c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861 c81bcc7c540eb1ca814514353dfb17ceed092dac0fb7de7446825287736cc166 d9d6fc3085dd822f258601164ecb21f318822a63ca0360aead9201bcee49ed04 f68ba32766e087f5a6855fa7da9feea2968280a019aec31d7d173adcd4b848ca MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.