Crytox is a Windows ransomware family active since at least 2020. It is a multi-stage 64-bit malware strain written in C and often distributed in packed form to hinder analysis. Crytox encrypts files on local disks and network drives, appends a characteristic extension to encrypted data, drops ransom notes, and gives victims a five-day payment deadline. Unlike many contemporary ransomware operations, Crytox has been reported primarily as an encryption-focused threat rather than a double-extortion platform, with no confirmed data-theft component in the analyzed operations.
Technically, Crytox uses layered encrypted configurations, API hashing, shellcode staging, and remote thread injection into native Windows processes to evade static and behavioral detection. Observed stages include deletion of volume shadow copies, clearing of forensic artifacts, and process injection into legitimate system processes before launching the final encryption routine. The malware dynamically resolves Win32 APIs at runtime, uses mutexes to coordinate execution, and attempts to reduce recoverability by removing backups and erasing traces of earlier stages from disk.
Crytox stores or generates RSA key material locally and uses per-file symmetric encryption keys protected with asymmetric cryptography. Analyses have described per-file AES encryption combined with RSA protection of key material, as well as victim-specific identifiers embedded into renamed files and ransom workflows. The malware also drops the uTox messenger client to facilitate victim communication with the operators and uses an HTA-based ransom note mechanism, including persistence to re-display the note after reboot.
Operational reporting links Crytox to ransomware intrusions involving compromised remote access, exploitation of public-facing applications, and post-compromise deployment after endpoint defenses were weakened. Multiple incident reports describe Crytox being used alongside EDR-disabling tooling, including HRSword and kernel-driver-based security killers delivered through packers or side-loading chains. Crytox has appeared in broader ransomware ecosystems where tooling is shared across affiliates or operators, and it has been observed affecting enterprise environments including virtualized infrastructure and sectors such as manufacturing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The shellcode is injected into this target process, using the conventional API’s VirtualAllocEx, WriteProcessMemory, and NtCreateThreadEx is invoked to execute the shellcode in a new thread.
Cryptox uses different techniques to thwart static analysis including the following: API hashing Encrypted configurations Encrypted shellcode Remote thread injection
Win32 APIs are dynamically resolved at runtime, it uses ROR7 for calculating module/DLL name hash, and ROR5 for calculating the export API hash.
The shellcode is injected into this target process, using the conventional API’s VirtualAllocEx, WriteProcessMemory, and NtCreateThreadEx is invoked to execute the shellcode in a new thread.
According to this decrypted configuration, the shellcode executes a batch file to delete shadow copies and remove events from the logs. Essentially the following commands are run:: for /F "tokens=*" %%1 in ('wevtutil.exe el') DO wevtutil.exe cl "%%1"
Probably to evade memory forensic, the stage-1 file is completely filled with NULL bytes and saved, before deleting it from disk.
The injected shellcode checks if the target process has “SeDebugPrivilege” Enabled. If it is, then the Access Token is updated to NTAuthority/SYSTEM.
Once a Quick Assist session is established, the adversary loads tooling to collect information about the target system and establish persistence... disable endpoint protections... Of note, we also observed the affiliates using HRSword to disable the target’s EDR solution.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage ransomware first observed in 2020 that encrypts local and network drives, drops the uTox messenger client for victim negotiation, uses AES-CBC with a unique 256-bit key per file protected by a locally generated RSA key pair, and appends a .waiting-style extension. The analyzed implementation does not perform data exfiltration and contains a weak key-generation design that may allow plaintext-assisted brute-force recovery in some cases.
A ransomware family explicitly mentioned as using the Shanya-protected EDR killer in operations.
Ransomware family observed in attacks where EDR-killer tools precede ransomware deployment.
Ransomware family first seen in 2020 that encrypts local disks and network drives and drops a ransom note with a five-day ultimatum. In the observed incident, actors exploited a public-facing application lacking MFA, encrypted two hypervisors hosting numerous VM servers, used uTox for communication, and used HRSword to disable EDR.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.