Skip to content

CryptoWall

CryptoWall is a Windows ransomware family that emerged as a major successor to CryptoLocker-era extortion malware and became one of the most prominent cryptomalware threats of the mid-2010s.

Profile source: Mallory opens in a new tab

CryptoWall

Family profile

CryptoWall is a Windows ransomware family that emerged as a major successor to CryptoLocker-era extortion malware and became one of the most prominent cryptomalware threats of the mid-2010s. It encrypts victim files and presents ransom instructions, typically leveraging Tor-based payment infrastructure and Bitcoin payments. Multiple later ransomware families borrowed visual elements, ransom-note templates, or branding cues from CryptoWall, reflecting its influence on the ransomware ecosystem.

CryptoWall was widely distributed through several criminal delivery channels and affiliate ecosystems. Reported distribution methods included exploit kits such as Magnitude, malspam operations, and downloader chains involving malware such as Upatre. Campaign reporting also linked CryptoWall-related activity to broader spam and malware-delivery ecosystems that reused shared affiliates or intermediate payloads.

The family is associated with iterative development across versions. CryptoWall 2 was noted for adding stronger anti-debugging and anti-analysis measures, while some of those features were reportedly reduced in CryptoWall 3. Its prominence led to frequent imitation by other ransomware families, including reuse of its HTML payment pages and ransom-note styling.

CryptoWall primarily targeted Windows systems and was part of the broader global surge in ransomware activity observed from 2014 onward. It was commonly referenced alongside major contemporaries such as CryptoLocker, CTB-Locker, TeslaCrypt, Cerber, and later GandCrab as one of the defining ransomware families of its period.

Capabilities

  • Defense Evasion
  • Extortion

Exploited software

Vulnerabilities linked to CryptoWall

1 CVEs

MITRE ATT&CK

CryptoWall in ATT&CK

7 distinct techniques

Reporting

Research mentioning CryptoWall

Dec 16
Eset Welivesecurity

Nemucod malware spreads ransomware Teslacrypt

TeslaCrypt emerged as a fast-moving ransomware family that encrypted both common user documents and game-related files, including saved games and Steam-related data, expanding its impact to PC gamers. Initial infections were linked to malicious email attachments and exploit kits such as Angler, which abused browser and plugin flaws including Adobe Flash CVE-2015-0311; later distribution was also tied to Sweet Orange and Nuclear via compromised websites. The malware deleted Volume Shadow Copies, contacted command-and-control infrastructure, and used ransom notes and recovery files to pressure victims into paying in Bitcoin. Later TeslaCrypt variants significantly hardened their cryptography and extortion workflow. Researchers reported that early versions falsely claimed to use RSA-2048 while actually relying on AES-CBC-256, with key material stored locally in files such as key.dat, allowing decryption in some cases and enabling Cisco Talos to release a recovery utility when the necessary keys were present. TeslaCrypt 2.0, however, adopted a stronger design using ECDH over secp256k1 with AES-256-CBC, moved key-related data into the Windows registry, generated unique Bitcoin addresses per victim, appended the .zzz extension to encrypted files, and replaced its interface with an HTML ransom page modeled on CryptoWall, making recovery without attacker-controlled key material far more difficult.

Oct 9
Paloalto Researchcenter Historic

Latest TeslaCrypt Ransomware Borrows Code From Carberp Trojan

Jul 18
Securelist

TeslaCrypt 2.0 disguised as CryptoWall | Securelist

Apr 27
Cisco Talos

Threat Spotlight: TeslaCrypt - Decrypt It Yourself - Cisco Blogs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.