Crypt Ghouls is a cybercriminal ransomware actor identified in attacks against Russian businesses and government agencies. Victimology includes organizations in the public sector as well as mining, energy, finance, and retail. The group’s operations have been assessed as pursuing both operational disruption and financial gain. Observed intrusion chains show initial access through compromised contractor or subcontractor credentials used over VPN, indicating abuse of trusted third-party relationships. After access, the group has established persistence and remote administration with tools such as NSSM, Localtonet, AnyDesk, and resocks. Post-compromise activity includes credential theft using Mimikatz and XenAllPasswordPro, Kerberos ticket dumping, browser credential collection, and attempts to access Active Directory data including NTDS extraction. Reconnaissance and lateral movement have involved PingCastle, SoftPerfect Network Scanner, WMI, PsExec, and PAExec. Crypt Ghouls has also used a CobInt loader delivered via VBScript and obfuscated PowerShell, and has employed DLL sideloading for payload execution. For impact, Crypt Ghouls has deployed LockBit 3.0 on Windows systems and Babuk on Linux and ESXi environments. Reported ransomware behavior includes disabling security controls, deleting event logs, terminating selected processes and services, and encrypting virtual-machine-hosted data after SSH access to ESXi servers. The actor leaves ransom instructions and has been linked to extortion-oriented ransomware operations. Multiple investigations have identified substantial overlaps between Crypt Ghouls and other Russia-targeting clusters including MorLock, BlackJack, Twelve, and Shedding Zmiy (ExCobalt). Shared elements include tooling, naming conventions, infrastructure patterns, and tradecraft, suggesting collaboration, shared resources, or exchange of tooling and operational knowledge rather than a cleanly isolated cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor that used AnyDesk alongside other tools during operations.
Hacktivist group active against Russian organizations, motivated by disruption and public pressure.
Ransomware-focused group targeting Russian businesses and government agencies, using compromised contractor VPN credentials, credential theft, WMI/RDP-based lateral movement, reconnaissance utilities, and deploying LockBit 3.0 on Windows and Babuk on Linux/ESXi systems.
Ransomware intrusion activity leveraging compromised contractor/subcontractor credentials (VPN initial access), followed by lateral movement/persistence tooling and deployment of LockBit 3.0 (Windows) and Babuk (Linux/ESXi) to encrypt victim data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.