logo

CryptNet Ransomware

ID: 6e9a11b1-993f-53f3-8f73-971d581d3f1e

STIX ID: report--6e9a11b1-993f-53f3-8f73-971d581d3f1e

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of the CryptNet ransomware: its NET Reactor obfuscation and custom string decryption, generation of a unique decryption ID, AES-CBC per-file encryption with RSA-2048-wrapped keys, targeted file extensions and exclusions, partial/full-file encryption behavior, and destructive post-encryption actions (killing processes/services, deleting shadow copies). It also describes the ransom note format, a Tor-based victim portal with test-decrypt and chat support, and a public data-leak blog used by the operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.