CryLock is a Delphi-based ransomware family from the Russian-language cybercrime ecosystem that has operated since roughly 2014, originally under the name Cryakl or Crykal before rebranding as CryLock in 2020. It has been offered through a ransomware-as-a-service model in which core operators develop and maintain the malware while affiliates deploy it against victim environments. Law-enforcement action later linked the operation to a Russian developer and associated deployment activity on thousands of systems.
CryLock encrypts victim files using asymmetric cryptography together with a custom symmetric routine and drops an HTML Application ransom note. The family has also been associated with extortion workflows that go beyond encryption, including theft of unencrypted data, operation of leak or auction-style infrastructure, and threats to sell stolen information if victims refuse to pay. This places CryLock among ransomware operations that adopted double-extortion and data-theft pressure tactics.
The malware includes regional checks intended to avoid infecting systems in Commonwealth of Independent States countries, a pattern commonly seen in Russia-linked criminal malware. A companion utility associated with the ecosystem has been used to locate CryLock-encrypted files across local and network storage and determine the encryption generation used. CryLock has been referenced as one of the more aggressive ransomware operations affecting organizations in Russia, and reporting has noted tradecraft overlap between CryLock operators and the later Trigona ransomware activity, suggesting possible personnel or operational continuity, although that linkage is not conclusively established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actor utilized the CryLock ransomware to encrypt the victim’s environment. | CryLock is a ransomware from the Russian cybercrime underground. It follows a Ransomware-as-a-Service (RaaS) model, where “partners” (or “affiliates”) acquire the ransomware to deploy it in victim environments.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Ransomware family cited as a source of leaked code/builders used to create new variants.
Ransomware family operated as an early ransomware-as-a-service (RaaS) model; article references operators, victim scale, and criminal proceeds.
Ransomware family referenced in the context of law-enforcement action against its developer for large-scale deployment and extortion activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.