A ransomware operation run by a Russian couple, accumulating 400,000 victims and over €64 million.
Analyst brief
CryLock (originally known as Cryakl/Fantomas since 2014) was a ransomware operation run by a Russian couple who accumulated roughly 400,000 victims and over €64 million in Bitcoin. They primarily targeted individual users over an eight-year period. Their primary TTPs involved ransomware encryption, though no specific tools are detailed in the provided data. Defenders should note that the operators were arrested in Spain in June 2023 and extradited to Belgium, but should remain vigilant for any legacy ransomware IOCs from this long-running campaign.
crylock
crime
CryLock (originally known as Cryakl/Fantomas since 2014) is a ransomware operation run by a Russian couple who targeted roughly 400,000 victims over eight years and earned over €64 million in Bitcoin; the operators were arrested in Spain in June 2023 and extradited to Belgium.
Who were the primary targets of the CryLock ransomware operation?+
CryLock primarily targeted individual users, infecting roughly 400,000 victims over an eight-year period.
What should defenders consider regarding the arrest of the CryLock operators?+
Defenders should note that the operators were arrested in Spain in June 2023 and extradited to Belgium, but should continue monitoring for any ransomware IOCs based on their eight years of activity.