CryptoTech is a cybercriminal group known for selling the Hermes 2.1 ransomware on the exploit.in underground forum beginning in February 2017. The group publicly claimed responsibility for Hermes 2.1 in June 2018 and announced a forthcoming new Hermes version, after which no further Hermes releases were observed other than Ryuk, a ransomware family widely described as a Hermes 2.1 variant. CryptoTech subsequently ceased activity on the forum. Although this sequence has led to longstanding speculation about a relationship between CryptoTech and Ryuk, high-confidence attribution of Ryuk operations directly to CryptoTech remains unconfirmed. CryptoTech is therefore primarily associated with ransomware development and distribution rather than with a fully documented intrusion set. Through Hermes 2.1, the group is linked to financially motivated cybercrime and the provision of ransomware tooling to other actors. Broader reporting around Hermes and Ryuk has also noted that Hermes was obtained and used by other threat actors, indicating that CryptoTech’s malware was available beyond a single operator ecosystem. The most defensible characterization of CryptoTech is as a criminal ransomware developer/vendor tied to Hermes 2.1, with a possible but unverified connection to the later emergence of Ryuk.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.