Skip to content

CryptoMix

CryptoMix is a Windows ransomware family active since at least 2016 and known for numerous variants including Azer, Revenge, WORK, Mole02, and the lineage that later became associated with Clop.

Profile source: Mallory opens in a new tab

CryptoMix

Family profile

CryptoMix is a Windows ransomware family active since at least 2016 and known for numerous variants including Azer, Revenge, WORK, Mole02, and the lineage that later became associated with Clop. It encrypts victim files and renames them with variant-specific extensions, then drops ransom notes instructing victims to contact the operators for payment and decryption. Multiple variants use hybrid cryptography, with file data encrypted using AES and the symmetric key protected with embedded RSA public keys. Some variants operate fully offline without network communication during encryption.

Observed CryptoMix variants show substantial anti-recovery and enterprise-impact functionality. Samples have been documented deleting shadow copies, disabling Windows recovery features, stopping security services, and terminating database or business-critical processes so locked files can be encrypted. Certain variants also use social engineering to obtain elevated execution, while others have been linked to manually executed intrusions in enterprise environments. Revenge was distributed via the RIG exploit kit through compromised websites, while Clop-branded CryptoMix variants were assessed as likely deployed after attackers gained access to exposed Remote Desktop Services and then executed the ransomware manually across networks.

The family has evolved over time from earlier consumer-focused file encryption toward broader enterprise ransomware operations. Clop is widely regarded as having originated as a CryptoMix variant and later became associated with TA505/Cl0p activity. Clop-era variants were notable for stopping numerous services and processes tied to mail, database, and backup software before encryption, reflecting an emphasis on maximizing operational disruption in corporate environments. CryptoMix and its descendants have been observed using code-signed executables, changing ransom-note branding and file extensions frequently, and maintaining variant-specific contact infrastructure while preserving core encryption and extortion behavior.

Targeting has included general Windows systems as well as enterprise networks, with particular impact on organizations running exposed remote administration services or vulnerable web-facing software. No universal free decryption capability is supported across the family; recoverability has depended on the specific variant and implementation flaws, if any, present at the time of discovery.

Capabilities

  • Defense Evasion
  • Extortion

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 3, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • NL1

Leading providers

  • WorldStream B.V.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TA505

The Clop ransomware gang, aka TA505 and Cl0p, launched in March 2019, when it first began targeting the enterprise using a variant of the CryptoMix ransomware.

MITRE ATT&CK

CryptoMix in ATT&CK

12 distinct techniques

Reporting

Research mentioning CryptoMix

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

Jan 1
Zscaler Threat Labz

MINEBRIDGE Remote-access Trojan (RAT) 2021 | Zscaler Blog

Attackers used the legitimate Windows finger.exe utility in a phishing campaign to download and install the MineBridge backdoor, turning a rarely used Windows command into a living-off-the-land malware delivery tool. The lures arrived as malicious Word documents disguised as job applicant resumes, and victims who enabled editing or content triggered a password-protected macro that fetched a Base64-encoded payload from a remote server. The payload was written to %AppData%, decoded with certutil.exe, and executed, showing how multiple native Windows tools were chained together to avoid suspicion. The downloader then retrieved a TeamViewer executable and used DLL hijacking to sideload MineBridge, ultimately giving the attackers broad remote access to infected systems. Reported capabilities included command execution, file download, process control, system information collection, and microphone access through TeamViewer. FireEye had previously linked MineBridge to phishing activity targeting South Korean organizations, indicating the campaign fit an established pattern of malware delivery and post-compromise remote control.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.