CryptoMix is a Windows ransomware family active since at least 2016 and known for numerous variants including Azer, Revenge, WORK, Mole02, and the lineage that later became associated with Clop. It encrypts victim files and renames them with variant-specific extensions, then drops ransom notes instructing victims to contact the operators for payment and decryption. Multiple variants use hybrid cryptography, with file data encrypted using AES and the symmetric key protected with embedded RSA public keys. Some variants operate fully offline without network communication during encryption.
Observed CryptoMix variants show substantial anti-recovery and enterprise-impact functionality. Samples have been documented deleting shadow copies, disabling Windows recovery features, stopping security services, and terminating database or business-critical processes so locked files can be encrypted. Certain variants also use social engineering to obtain elevated execution, while others have been linked to manually executed intrusions in enterprise environments. Revenge was distributed via the RIG exploit kit through compromised websites, while Clop-branded CryptoMix variants were assessed as likely deployed after attackers gained access to exposed Remote Desktop Services and then executed the ransomware manually across networks.
The family has evolved over time from earlier consumer-focused file encryption toward broader enterprise ransomware operations. Clop is widely regarded as having originated as a CryptoMix variant and later became associated with TA505/Cl0p activity. Clop-era variants were notable for stopping numerous services and processes tied to mail, database, and backup software before encryption, reflecting an emphasis on maximizing operational disruption in corporate environments. CryptoMix and its descendants have been observed using code-signed executables, changing ransom-note branding and file extensions frequently, and maintaining variant-specific contact infrastructure while preserving core encryption and extortion behavior.
Targeting has included general Windows systems as well as enterprise networks, with particular impact on organizations running exposed remote administration services or vulnerable web-facing software. No universal free decryption capability is supported across the family; recoverability has depended on the specific variant and implementation flaws, if any, present at the time of discovery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Clop ransomware gang, aka TA505 and Cl0p, launched in March 2019, when it first began targeting the enterprise using a variant of the CryptoMix ransomware.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 has been leveraging the Get2 loader using the same crypter since at least September 2019... the crypter has remained the same with a few modifications every few months.
This variant is currently being distributed using executables that have been code-signed with a digital signature. Doing so makes the executable appear more legitimate and may help to bypass security software detections.
This version of Cryptomix ransomware encrypts files in a similar manner to all others in this family... when a file is encrypted by the ransomware, it will modify the filename and then append the string -email-[email_address].AZER to the encrypted file.
when started this variant will first stop numerous Windows services and processes in order to disable antivirus software and close all files so that they are ready for encryption.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family referenced as the likely lineage/base variant for Clop, dating back to 2016 (per the content).
A ransomware family referenced as the basis for the early Clop variant when the gang began operations.
Named as ransomware associated with actors using the same crypter overlap discussed in the article.
Ransomware family referenced as the lineage/variant base for early CL0P.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.