DiskCryptor is a legitimate open-source full-disk encryption utility for Windows that has been repeatedly weaponized by ransomware and disruptive intrusion operators to deny access to victim systems. In malicious use, attackers employ DiskCryptor’s core disk-encryption and boot-level capabilities to encrypt entire volumes, including operating system partitions, sometimes alongside custom boot-loader or master boot record modifications to lock systems before normal startup. Because DiskCryptor is a legitimate administrative tool rather than malware by design, it is commonly abused as part of broader ransomware workflows instead of functioning as a standalone malicious family.
Threat actors associated with DiskCryptor abuse include Mamba, Moses Staff, and Iranian-linked COBALT MIRAGE/PHOSPHORUS activity. Mamba is known for wrapping DiskCryptor in a custom program that installs the utility, launches full-disk encryption with an attacker-supplied key, and forces reboots to complete encryption and present a ransom demand. Moses Staff and related tooling such as DCSrv have used DiskCryptor’s encryption mechanisms to block access to computers and encrypt all volumes, while also abusing signed DiskCryptor drivers for defense evasion. Separate ransomware intrusions attributed to PHOSPHORUS/COBALT MIRAGE used DiskCryptor to encrypt Windows workstations, often in conjunction with BitLocker on servers.
Observed malicious deployment of DiskCryptor follows prior compromise rather than serving as an initial-access mechanism itself. Reported intrusion chains leading to DiskCryptor use have included exploitation of public-facing applications such as Microsoft Exchange ProxyShell and opportunistic scan-and-exploit activity against exposed enterprise infrastructure. Once deployed, DiskCryptor contributes primarily to impact and extortion objectives by rendering systems unbootable or inaccessible until a decryption key is provided. Its use of legitimate signed components can also reduce suspicion and complicate detection in enterprise environments.
DiskCryptor targets and runs on Windows systems. Organizations affected in campaigns that weaponized DiskCryptor have included government, transportation, legal, technology, industrial, manufacturing, construction, and critical-infrastructure entities, as well as Israeli organizations targeted in geopolitically motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DCSrv blocks all access to the computer and encrypts all its volumes using the legitimate open-source encryption utility DiskCryptor.
DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
This same script would also deploy the ONI ransomware on computers in order to encrypt files and to possibly further obfuscate the activities of the attackers.
DCSrv blocks all access to the computer and encrypts all its volumes using the legitimate open-source encryption utility DiskCryptor.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate disk encryption software abused by threat actors to encrypt victim systems as part of ransomware-style attacks.
DiskCryptor is used by Moses Staff as a tool, including its signed drivers to evade detection.
Open-source full-disk encryption utility used by the intruders to encrypt (lock out) Windows workstations for impact, requiring reboots to install a kernel-mode driver and complete encryption.
A legitimate open-source disk encryption utility abused by DCSrv to encrypt victim volumes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.