Crux is a Windows ransomware variant first observed in July 2025 in multiple intrusions. It encrypts victim files and leaves ransom notes. Operators have claimed an affiliation with the BlackByte ransomware group, but that relationship has not been independently validated. Observed intrusions used a distinctive execution chain in which an unsigned ransomware executable launched svchost.exe, followed by cmd.exe and bcdedit.exe, to alter boot configuration and inhibit system recovery before encryption. In one confirmed intrusion, access was obtained through valid credentials used over Remote Desktop Protocol; initial access was not determined in other cases. Related activity included remote Registry dumping, kernel-driver installation, creation of user accounts, lateral movement, and Rclone-based data exfiltration. The malware and associated activity target Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Another new entrant to the ransomware landscape is Crux, which claims to be part of the BlackByte group and has been deployed in the wild...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware was launched within seven minutes of an initial test login, apparently using valid credentials to verify access... EDR telemetry and endpoint session information showed the threat actor compromised and used a support user account, and also accessed the endpoint via the administrator account.
The ransomware was launched within seven minutes of an initial test login, apparently using valid credentials to verify access... EDR telemetry and endpoint session information showed the threat actor compromised and used a support user account, and also accessed the endpoint via the administrator account.
The ransomware was launched within seven minutes of an initial test login, apparently using valid credentials to verify access... EDR telemetry and endpoint session information showed the threat actor compromised and used a support user account, and also accessed the endpoint via the administrator account.
Before encrypting files, the ransomware executable launches the legitimate svchost.exe , albeit with a distinctive command line... The legitimate Windows process svchost.exe runs multiple Windows services; however, threat actors can misuse it to disguise their commands.
The ransomware was launched within seven minutes of an initial test login, apparently using valid credentials to verify access... EDR telemetry and endpoint session information showed the threat actor compromised and used a support user account, and also accessed the endpoint via the administrator account.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An emerging ransomware strain mentioned only as contextual comparison to Settra.
Mentioned as a newer ransomware family for context; no technical details provided in the content.
A previously unpublished ransomware variant mentioned for comparison.
Ransomware observed in the wild; intrusions described include use of valid RDP credentials for access and living-off-the-land execution/defense evasion using legitimate Windows processes (e.g., svchost.exe, bcdedit.exe) to conceal commands and inhibit recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.