logo

Technical Analysis of Crytox Ransomware

ID: 705f7b77-dd3b-5f7b-9547-4e0ed692f87f

STIX ID: report--705f7b77-dd3b-5f7b-9547-4e0ed692f87f

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of the Crytox ransomware (active since 2020), describing its multi-stage infection chain, use of embedded uTox for victim communication, AES-CBC file encryption with per-file 256-bit keys protected by a locally generated RSA key, persistence mechanisms, and observable Indicators of Compromise (hashes, dropped ReadMe.hta, .waiting extension, and registry keys). It highlights a practical weakness in Crytox's pseudo-random AES key generation (seeded by GetTickCount) that enables known-plaintext brute-force recovery of keys for some file types.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.