CryptXXX is a Windows ransomware family active in 2016 and commonly associated with exploit-kit-driven infections, particularly Angler EK campaigns that also delivered Bedep. It encrypts victim files and presents ransom instructions for paid decryption. Observed infections used a DLL payload executed through a dropped copy of rundll32.exe masquerading as another Windows binary, and the malware communicated with command-and-control infrastructure over raw TCP on port 443 using custom encoding rather than standard TLS. CryptXXX is also notable for technical lineage and implementation similarities later observed in DanaBot and earlier Reveton malware, including Delphi development and comparable command-and-control design choices. High-confidence reporting ties CryptXXX to opportunistic cybercrime activity rather than a specific state actor, with delivery focused on compromised web traffic redirected into exploit kits and subsequent ransomware deployment on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
I saw svchost.exe (actually: rundll32.exe) in the same folder as the CryptXXX ransomware.
I saw svchost.exe (actually: rundll32.exe) in the same folder as the CryptXXX ransomware. It was used to run the CryptXXX ransomware .dll file.
After that, Bedep acts differently. You'll see Bedep contacting 95.211.205[.]228 after Bedep detects it's running on a VM, and it will download different malware. As usual, no CryptXXX ransomware when doing the Angler EK/Bedep infection with a VM, and any click-fraud traffic is a ruse.
After that, Bedep acts differently. You'll see Bedep contacting 95.211.205[.]228 after Bedep detects it's running on a VM, and it will download different malware. As usual, no CryptXXX ransomware when doing the Angler EK/Bedep infection with a VM, and any click-fraud traffic is a ruse.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as earlier ransomware with technical similarities to DanaBot.
Ransomware delivered via the pseudo-Darkleech/Angler EK infection chain. It is dropped as a DLL, executed via rundll32.exe, encrypts files, and leaves decryption instructions in BMP, HTML, and TXT formats while communicating over custom-encoded TCP traffic on port 443.
CryptXXX is file-encrypting ransomware discussed as a likely predecessor in the malware lineage/protocol evolution leading to DanaBot. It shared Delphi implementation and custom TCP/443 C2 protocol traits with DanaBot.
DanaBot bears some similarities in its technical implementation and choices of technology to earlier malware, in particular Reveton and CryptXXX, which were also written in Delphi and communicated using raw TCP to port 443.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.