Crysis is a ransomware family and criminal operation associated with opportunistic intrusions, particularly smaller-scale attacks rather than large enterprise-wide “big game” campaigns. It has been linked to the use of defense-evasion tooling that disables Microsoft Defender after access is obtained, and reporting associates it with intrusion patterns involving exposed Remote Desktop Protocol services. In these cases, operators commonly compromise limited portions of an environment and may ransom a single system rather than conduct full domain-wide compromise. Crysis has been referenced alongside Dharma and Phobos as part of the ecosystem of smaller ransomware actors using straightforward post-compromise tradecraft focused on disabling endpoint protections and rapidly monetizing access. The operation is also notable for having shut down and released master decryption keys, enabling recovery for some victims. Available information in this context supports characterization of Crysis as a financially motivated ransomware threat actor using initial access through exposed remote services and defense evasion to facilitate encryption-based extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a smaller ransomware actor/group seen using Defender Control during intrusions, typically after initial access via exposed RDP and often ransoming a single system without fully compromising the domain.
Referenced as a ransomware operation that released master decryption keys upon shutdown.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.