CryptoLocker is a Windows file-encrypting ransomware family that emerged in September 2013. It affected consumers and organizations worldwide, with infections concentrated in English-speaking countries, particularly the United States. It is associated with the Gameover Zeus cybercriminal operation and was distributed through malicious email attachments and an infection chain involving the Cutwail spam botnet, Upatre downloader, and Gameover Zeus. Distribution also involved Gameover Zeus infections delivered through the Blackhole and Magnitude exploit kits.
CryptoLocker establishes persistence through autorun entries and communicates with command-and-control infrastructure using HTTP, encrypted messages, hard-coded destinations, and a domain generation algorithm. It obtains an attacker-controlled RSA public key before encrypting files. Using Microsoft CryptoAPI, it encrypts each targeted file with a unique AES-256 key and protects that key with RSA. It targets documents, databases, design files, certificates, images, and other valuable data on local disks and accessible network drives; later versions also target removable drives.
After encryption, CryptoLocker displays a ransom demand with a countdown timer and offers decryption in exchange for payment, including Bitcoin and prepaid payment services. Its operators also introduced a higher-priced recovery service for victims who missed the original payment deadline. Strong cryptography made recovery dependent on access to the corresponding private keys or unaffected backups. A multinational law-enforcement operation disrupted related Gameover Zeus infrastructure and seized servers central to CryptoLocker in June 2014. Other ransomware families subsequently reused CryptoLocker's name or interface without necessarily belonging to the original family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malware proceeds through a number of checks for the presence of virtual machines or antivirus before dropping a Flash exploit for CVE-2015-0311 or an Internet Explorer exploit CVE-2013-2551.
The malware proceeds through a number of checks for the presence of virtual machines or antivirus before dropping a Flash exploit for CVE-2015-0311 or an Internet Explorer exploit CVE-2013-2551.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Individual operators often dropped other malware • CryptoLocker – first in-house development, destructive
20 distinct techniques documented for this family, organized by ATT&CK tactic.
the samples were downloaded from a compromised website located in the United States... Gameover Zeus has also been distributed by the Blackhole and Magnitude exploit kits.
The malware begins the encryption process by using the GetLogicalDrives() API call to enumerate the disks on the system that have been assigned a drive letter.
Initially peer-to-peer + traditional comms via gameover2.php
CryptoLocker cycles indefinitely until it connects to a C2 server via HTTP.
This service is available by connecting directly to a Command & Control server's IP address or hostname or through Tor via the f2d2v7soksbskekh.onion/ address.
GOZ includes code that permits the defendants to install additional malicious software onto computers infected with GOZ. The defendants and their co-conspirators have used this capability to install Cryptolocker onto numerous computers within the GOZ botnet.
This decryption service can also be accessed via TOR at the address f2d2v7soksbskekh.onion/.
The malware's network communications use an internal domain generation algorithm (DGA) that produces 1,000 potential C2 domain addresses per day.
CryptoLocker changes this dynamic by aggressively encrypting files on the victim's system... Each file is encrypted with a unique AES key, which in turn is encrypted with the RSA public key received from the C2 server.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
79 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware explicitly identified as a payload distributed by GameOver Zeus.
Referenced as additional malware distributed by Gameover Zeus.
Referenced as a ransomware family that used TOR-based victim communication, contrasted with Petya and NotPetya's email-based approach.
Referenced as a previous ransomware example for comparison with WannaCry's TOR-based C2 design.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.