logo

Cronus: Ransomware Threatening Bodily Harm

ID: a98e0a54-9c88-5088-a58f-24e54d78729f

STIX ID: report--a98e0a54-9c88-5088-a58f-24e54d78729f

Feed Name: Pulsedive Blog

Threat Score
60/100

Date Published: 2024-10-17

Date Updated: 2026-04-28

Author: Pulsedive Threat Research

...
...

This report analyses the Cronus .NET ransomware: it is delivered via a malicious PayPal-themed document that triggers PowerShell to load a Cronus DLL, which establishes persistence by copying to C:\Users\<USERNAME>\AppData\Local and adding a registry Run key, discovers and excludes specific folders/files, terminates targeted processes, and encrypts a wide range of file types (AES-256 CBC; larger files encrypted in three parts) while appending random 5-character extensions; the dropped ransom note demands US$500 in Bitcoin and claims data exfiltration but public telemetry suggests limited observed activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.