CryptoWall is a Windows ransomware family that emerged as a major successor to CryptoLocker-era extortion malware and became one of the most prominent cryptomalware threats of the mid-2010s. It encrypts victim files and presents ransom instructions, typically leveraging Tor-based payment infrastructure and Bitcoin payments. Multiple later ransomware families borrowed visual elements, ransom-note templates, or branding cues from CryptoWall, reflecting its influence on the ransomware ecosystem.
CryptoWall was widely distributed through several criminal delivery channels and affiliate ecosystems. Reported distribution methods included exploit kits such as Magnitude, malspam operations, and downloader chains involving malware such as Upatre. Campaign reporting also linked CryptoWall-related activity to broader spam and malware-delivery ecosystems that reused shared affiliates or intermediate payloads.
The family is associated with iterative development across versions. CryptoWall 2 was noted for adding stronger anti-debugging and anti-analysis measures, while some of those features were reportedly reduced in CryptoWall 3. Its prominence led to frequent imitation by other ransomware families, including reuse of its HTML payment pages and ransom-note styling.
CryptoWall primarily targeted Windows systems and was part of the broader global surge in ransomware activity observed from 2014 onward. It was commonly referenced alongside major contemporaries such as CryptoLocker, CTB-Locker, TeslaCrypt, Cerber, and later GandCrab as one of the defining ransomware families of its period.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
Ransomware family referenced as an example of recognized ransomware strains.
Named as a ransomware family delivered by Magnitude Exploit Kit.
Referenced as an earlier large-scale ransomware operation whose shutdown left space later filled by GandCrab.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.