CryLock
CryLock is a Delphi-based ransomware family from the Russian-language cybercrime ecosystem that has operated since roughly 2014, originally under the name Cryakl or Crykal before rebranding as CryLock in 2020.
Profile source: Mallory opens in a new tabCryLock
Family profile
CryLock is a Delphi-based ransomware family from the Russian-language cybercrime ecosystem that has operated since roughly 2014, originally under the name Cryakl or Crykal before rebranding as CryLock in 2020. It has been offered through a ransomware-as-a-service model in which core operators develop and maintain the malware while affiliates deploy it against victim environments. Law-enforcement action later linked the operation to a Russian developer and associated deployment activity on thousands of systems.
CryLock encrypts victim files using asymmetric cryptography together with a custom symmetric routine and drops an HTML Application ransom note. The family has also been associated with extortion workflows that go beyond encryption, including theft of unencrypted data, operation of leak or auction-style infrastructure, and threats to sell stolen information if victims refuse to pay. This places CryLock among ransomware operations that adopted double-extortion and data-theft pressure tactics.
The malware includes regional checks intended to avoid infecting systems in Commonwealth of Independent States countries, a pattern commonly seen in Russia-linked criminal malware. A companion utility associated with the ecosystem has been used to locate CryLock-encrypted files across local and network storage and determine the encryption generation used. CryLock has been referenced as one of the more aggressive ransomware operations affecting organizations in Russia, and reporting has noted tradecraft overlap between CryLock operators and the later Trigona ransomware activity, suggesting possible personnel or operational continuity, although that linkage is not conclusively established.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
Operational record
MITRE ATT&CK
CryLock in ATT&CK
9 distinct techniquesReporting
Research mentioning CryLock
Securonix Threat Research Security Advisory: New RE#TURGENCE Attack Campaign: Turkish Hackers Target MSSQL Servers to Deliver Domain-Wide MIMIC Ransomware - Securonix
Threat actors have been targeting poorly secured, internet-exposed Microsoft SQL Server instances to deliver Mimic and Trigona ransomware, using brute-force or weak credentials and, in some cases, xp_cmdshell for command execution. Researchers reported that one actor used the SQL Server Bulk Copy Program (BCP) utility to rebuild malware from database contents onto disk, while other intrusions relied on PowerShell download cradles, mounted SMB shares, and remote access tools including AnyDesk. In multiple cases, the attackers established persistence, created administrator accounts, enabled credential theft opportunities such as the WDigest\UseLogonCredential registry setting, and deployed tooling including Mimikatz, PsExec, Advanced Port Scanner, Defender Control, and SDelete.