Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
TeslaCrypt is a Windows ransomware family first observed in early 2015 and widely regarded as one of the major crypto-ransomware threats of that period.
Profile source: Mallory opens in a new tabTeslaCrypt
TeslaCrypt is a Windows ransomware family first observed in early 2015 and widely regarded as one of the major crypto-ransomware threats of that period. It encrypts victim files and demands payment for decryption, targeting common user data such as documents, images, and videos, while also becoming notable for targeting game-related files including saved games and related assets. Over its evolution, TeslaCrypt used multiple victim-facing names and changed encrypted-file extensions and ransom-note formats across versions.
TeslaCrypt was distributed through several common crimeware channels, including malicious email attachments and exploit-kit-driven web compromises. Documented delivery included redirection from compromised or malicious websites to exploit kits such as Angler, Sweet Orange, and Nuclear, including exploitation of Adobe Flash Player vulnerability CVE-2015-0311. It was also delivered in downloader chains, including campaigns where Nemucod JavaScript downloaders retrieved TeslaCrypt payloads from the internet.
The malware established itself on infected systems by copying itself into user-accessible locations and creating autorun persistence. Multiple analyses documented privilege adjustment, deletion of Volume Shadow Copies, anti-analysis checks using COM-related techniques, process termination aimed at administrative and analysis tools, and process-hollowing-style execution in some variants. TeslaCrypt also evolved its internal obfuscation and API-resolution logic over time, with later variants borrowing code patterns associated with the leaked Carberp source.
TeslaCrypt’s cryptographic design changed significantly across versions. Early variants falsely claimed to use RSA-2048 while analyses showed they actually relied on symmetric encryption schemes for file encryption and had implementation weaknesses in key storage or recovery logic. Those weaknesses enabled defenders and researchers to build free decryption tools for affected versions. Later variants strengthened the design, including versions that used elliptic-curve Diffie-Hellman over secp256k1 to protect key material and AES-CBC for file encryption, making recovery without attacker-controlled key material substantially more difficult. By TeslaCrypt 3.x, previously known recovery methods for older variants were no longer effective, and some variants could complete encryption even without live command-and-control connectivity.
TeslaCrypt communicated with attacker infrastructure to register infections, transmit key-related material, and report encryption status. It also used Tor-related infrastructure and tor2web access patterns in some versions. The family was associated with large criminal distribution ecosystems and infrastructure, including the Avalanche fast-flux botnet environment. TeslaCrypt is frequently described as a derivative or successor in style to earlier ransomware such as CryptoLocker and later adopted visual or operational elements resembling CryptoWall.
TeslaCrypt underwent rapid development through 2015 and into 2016, with variants commonly referred to as TeslaCrypt 2.0 and 3.0 introducing notable changes in ransom presentation, key handling, and encrypted-file extensions. The family was eventually discontinued, and its shutdown became a notable milestone in ransomware history after free recovery options had already emerged for many victims of earlier versions.
C2 tracking
Derp observations, rolling seven-day window
Samples
Exploited software
MITRE ATT&CK
Reporting
Tycoon, also tracked as RedRum, Grinch, and in some reporting alongside Thanos-linked variants, emerged as a manually deployed ransomware threat against enterprise environments on both Windows and Linux. Operators were reported to gain access through vulnerable or exposed RDP services, then encrypt files with AES-256-GCM while protecting encryption keys with RSA-1024. The malware appended extensions including .redrum, .grinch, .thanos, .eruption, and .magneto, and dropped a ransom note named decryption.txt using contact addresses such as moncler@tutamail.com and moncler@cock.li. Reporting also tied the activity to broader Thanos ransomware development, a .NET-based RaaS ecosystem that enabled extensive customization, persistence, anti-analysis, and defense-evasion features across multiple later variants. The malware was described as deleting shadow copies and disabling recovery and firewall protections while avoiding some system files and directories to keep infected systems operational. Historical tracking indicates some early Hakbit-identified and RedRum samples could be decrypted, including with an Emsisoft decryptor, while later corrected Thanos-derived variants adopted stronger RSA-based encryption that generally prevented recovery without the attackers' private key.
TeslaCrypt emerged as a fast-moving ransomware family that encrypted both common user documents and game-related files, including saved games and Steam-related data, expanding its impact to PC gamers. Initial infections were linked to malicious email attachments and exploit kits such as Angler, which abused browser and plugin flaws including Adobe Flash CVE-2015-0311; later distribution was also tied to Sweet Orange and Nuclear via compromised websites. The malware deleted Volume Shadow Copies, contacted command-and-control infrastructure, and used ransom notes and recovery files to pressure victims into paying in Bitcoin. Later TeslaCrypt variants significantly hardened their cryptography and extortion workflow. Researchers reported that early versions falsely claimed to use RSA-2048 while actually relying on AES-CBC-256, with key material stored locally in files such as key.dat, allowing decryption in some cases and enabling Cisco Talos to release a recovery utility when the necessary keys were present. TeslaCrypt 2.0, however, adopted a stronger design using ECDH over secp256k1 with AES-256-CBC, moved key-related data into the Windows registry, generated unique Bitcoin addresses per victim, appended the .zzz extension to encrypted files, and replaced its interface with an HTML ransom page modeled on CryptoWall, making recovery without attacker-controlled key material far more difficult.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.