logo

CryptoLocker ransomware intelligence report

ID: e4c6edd4-d559-5bd7-b01b-25f1a58d501f

STIX ID: report--e4c6edd4-d559-5bd7-b01b-25f1a58d501f

Feed Name: Fox-IT blog

Threat Score
78/100

Date Published: 2014-08-06

Date Updated: 2026-04-27

Author: Fox It

...
...

CryptoLocker was a large-scale ransomware campaign active from September 2013 to May 2014 that was distributed by P2P ZeuS botnets. The malware encrypted user files with AES and protected the AES key with a server-generated RSA-2048 keypair per infection, making local recovery infeasible; victims were charged ransoms (initially $100, later up to $500). Over 545,000 infections were observed, about 1.3% of victims paid, and operators collected around 1,407 BTC (contributing to ≈$3M total); operators used fast-flux and TOR infrastructure and accepted MoneyPak and Bitcoin. U.S. law enforcement disrupted the operation in May 2014 and third-party services later helped victims recover private keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.