Skip to content

CryLock

CryLock is a Delphi-based ransomware family from the Russian-language cybercrime ecosystem that has operated since roughly 2014, originally under the name Cryakl or Crykal before rebranding as CryLock in 2020.

Profile source: Mallory opens in a new tab

CryLock

Family profile

CryLock is a Delphi-based ransomware family from the Russian-language cybercrime ecosystem that has operated since roughly 2014, originally under the name Cryakl or Crykal before rebranding as CryLock in 2020. It has been offered through a ransomware-as-a-service model in which core operators develop and maintain the malware while affiliates deploy it against victim environments. Law-enforcement action later linked the operation to a Russian developer and associated deployment activity on thousands of systems.

CryLock encrypts victim files using asymmetric cryptography together with a custom symmetric routine and drops an HTML Application ransom note. The family has also been associated with extortion workflows that go beyond encryption, including theft of unencrypted data, operation of leak or auction-style infrastructure, and threats to sell stolen information if victims refuse to pay. This places CryLock among ransomware operations that adopted double-extortion and data-theft pressure tactics.

The malware includes regional checks intended to avoid infecting systems in Commonwealth of Independent States countries, a pattern commonly seen in Russia-linked criminal malware. A companion utility associated with the ecosystem has been used to locate CryLock-encrypted files across local and network storage and determine the encryption generation used. CryLock has been referenced as one of the more aggressive ransomware operations affecting organizations in Russia, and reporting has noted tradecraft overlap between CryLock operators and the later Trigona ransomware activity, suggesting possible personnel or operational continuity, although that linkage is not conclusively established.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion

Operational record

1
YARA rules
1
Leak sites
0 available

MITRE ATT&CK

CryLock in ATT&CK

9 distinct techniques

Reporting

Research mentioning CryLock

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.