Last seven days
- First activity
- Sep 13, 2026
- Last activity
- Sep 18, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 2 hostnames
CryptoLocker is an early and highly influential Windows ransomware family first observed in 2013 and widely regarded as one of the first modern large-scale file-encrypting ransomware operations.
Profile source: Mallory opens in a new tabCryptoLocker
CryptoLocker is an early and highly influential Windows ransomware family first observed in 2013 and widely regarded as one of the first modern large-scale file-encrypting ransomware operations. Unlike earlier locker-style threats that primarily blocked access to the desktop, CryptoLocker encrypted victim files and demanded payment for decryption, helping establish the modern ransomware model.
CryptoLocker was distributed initially through spam campaigns carrying malicious attachments and later at scale through the Upatre downloader, the Gameover Zeus ecosystem, and the Cutwail botnet. Additional delivery through exploit-kit activity, including Blackhole and Magnitude, has also been reported. After execution, the malware established persistence in the user profile and configured autorun behavior to survive reboots. It then contacted command-and-control infrastructure using both hard-coded destinations and a domain generation algorithm.
Once active, CryptoLocker enumerated local drives, network shares, and later removable media, and encrypted a broad range of business and personal file types using strong cryptography implemented through Microsoft CryptoAPI. Reported analyses describe per-file symmetric encryption protected by attacker-controlled asymmetric keys, which made recovery without the corresponding private key impractical. The malware typically remained silent until encryption had completed, then presented a ransom interface with a payment deadline. Operators later added a decryption service for victims who missed the initial deadline.
CryptoLocker is closely associated with the Gameover Zeus criminal operation and has been linked in public reporting to the broader Russian-speaking cybercrime ecosystem around that botnet. It caused substantial global impact, with hundreds of thousands of infections reported during its active period and especially heavy victimization in English-speaking countries, including the United States. Its combination of resilient distribution, effective monetization, and strong encryption made it a defining ransomware threat and a template for many later families.
C2 tracking
Derp observations, rolling seven-day window
Samples
00fbfd60c18de3822041dab7a4ce75eb3d0de82e3872e1aafb80b272d49cc3b0 0d9f012e079915b57adf0d987ca90497e196a64bf1360be4480ff1c95b5d0112 418844027e421bd687d0301b70cb8f2b5ac81ee069db77fb0ca35aa1571c79ad b8bccab2af6c1cf89545897d9bcfac24a0be41721c3860e1a48cc2b8468e62d6 f426a2adc85e4d07a458aac73c0b33bb13dca76b5b45dd5d4f92ef5b9dfb992e 05dbb515120ec8a6a453c91833eacf432e67ffe89fd650ac704eefc6bf8de290 11cd6ea8bc99ebcf41362bc98405ca3458d91c64f398bcea3388aadeb49a00a5 b926a44910e4f4d55c53fdc6d9cdbfb043059355d55fb3595a3434bd69b1e7e3 e72b03d7ce71ec92460622726d6bc55228eb8a62d39e82d8749f45fe497ba35c f2d177f0733377db07cb939110c64e15e83fc15fbc3fe2787c86e1a2b13c3b8d Reported operators
Individual operators often dropped other malware β’ CryptoLocker β first in-house development, destructive
MITRE ATT&CK
Reporting
Security researchers reported that the Android malware family Xbot evolved from a stealthy SMS-focused trojan into a broader banking and ransomware threat distributed through third-party app markets rather than Google Play. The malware masqueraded as trusted apps including Google Play, Opera Browser, Android Market, and Minecraft, then hid its launcher icon after installation to avoid detection. Early variants primarily targeted users in Russia and Eastern Europe, monitoring incoming SMS messages for selected keywords, exfiltrating messages to command-and-control infrastructure, sending premium-rate texts, downloading additional APKs, and persisting across reboots. Later analysis found Xbot embedded in 22 malicious apps and expanded to phishing Google Play payment details and login credentials for multiple banking apps, including major Australian banks and at least one Russian bank. The trojan used activity hijacking and WebView overlays to present fake login and card-entry screens, stole SMS messages and contacts, abused device administrator privileges, and accepted remote commands from its operators. Researchers also found ransomware functions that could lock the device, set a password, encrypt files on external storage with a simple XOR routine, and demand a $100 PayPal My Cash Card payment, while added obfuscation and dormant call-recording code indicated active ongoing development.
TeslaCrypt emerged as a fast-moving ransomware family that encrypted both common user documents and game-related files, including saved games and Steam-related data, expanding its impact to PC gamers. Initial infections were linked to malicious email attachments and exploit kits such as Angler, which abused browser and plugin flaws including Adobe Flash CVE-2015-0311; later distribution was also tied to Sweet Orange and Nuclear via compromised websites. The malware deleted Volume Shadow Copies, contacted command-and-control infrastructure, and used ransom notes and recovery files to pressure victims into paying in Bitcoin. Later TeslaCrypt variants significantly hardened their cryptography and extortion workflow. Researchers reported that early versions falsely claimed to use RSA-2048 while actually relying on AES-CBC-256, with key material stored locally in files such as key.dat, allowing decryption in some cases and enabling Cisco Talos to release a recovery utility when the necessary keys were present. TeslaCrypt 2.0, however, adopted a stronger design using ECDH over secp256k1 with AES-256-CBC, moved key-related data into the Windows registry, generated unique Bitcoin addresses per victim, appended the .zzz extension to encrypted files, and replaced its interface with an HTML ransom page modeled on CryptoWall, making recovery without attacker-controlled key material far more difficult.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.