Crucio is a Windows ransomware family whose encryption logic has also been repurposed for destructive pseudo-ransomware operations. It encrypts victim files, appends a distinctive new extension, and changes the desktop wallpaper, but observed derivative uses of its code do not preserve encryption keys or provide a ransom note, making recovery impossible and indicating destructive intent rather than monetized extortion. Crucio code has been identified as a building block inside the GigaWiper malware framework, where its file-encryption routine was incorporated as an operator-selectable destructive command. Microsoft assessed that this shared code lineage links Crucio to a broader cluster of destructive tooling that also includes FlockWiper. Crucio has been referenced in public reporting and government advisories related to attacks affecting Israeli organizations and, in some reporting, critical infrastructure sectors such as water and energy, although broader actor attribution remains less certain than the code relationship itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Fake ransomware built on older code called Crucio. It encrypts files, adds a .candy extension, and changes the desktop wallpaper to an alarming warning image. There is no ransom note and no saved key, so there is nothing to pay and nothing to decrypt.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware generates random AES encryption keys and initialization vectors that are intentionally discarded after encryption. Unlike conventional ransomware operations, no mechanism exists for recovering encrypted files because the encryption material is never retained.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously separate malware family whose file encryption routines were incorporated into GigaWiper's unified framework.
A ransomware family whose code was reused in GigaWiper's fake ransomware component.
Шифровальщик, код которого использован в одном из модулей GigaWiper для необратимого уничтожения данных: файлы шифруются, получают расширение .candy, при этом ключ не сохраняется и записка о выкупе не оставляется.
A ransomware family from which GigaWiper's fake ransomware module is derived; in this context it is used as the basis for irreversible file encryption by discarding the keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.