Cryakl is a Windows ransomware family, also known in some campaigns as Fantomas, that emerged in 2014 and became one of the most prevalent file-encrypting threats affecting users in Russia, with additional victimization reported in countries including Germany, Belarus, Kazakhstan, Ukraine, Japan, Italy, and others. It is commonly classified as Trojan-Ransom.Win32.Cryakl and has been observed evolving through multiple versions with changing file-naming conventions, encryption routines, and key-handling methods.
Cryakl is typically written in Delphi and encrypts selected portions of victim files rather than always processing entire files. Early variants encrypted the first bytes of a file plus additional blocks at random offsets, while later variants increased the encrypted portion. The malware appends metadata to encrypted files, including information needed to track encrypted regions, victim identifiers, and markers used by the malware family. Across its evolution, Cryakl used custom symmetric encryption schemes combined in later versions with RSA to protect per-file or session key material, which historically made decryption impractical without access to attacker-held private keys.
The malware targets a broad range of user and business data, including office documents, archives, disk images, backup-related files, databases, images, and other valuable content. After encryption, Cryakl commonly renames files according to structured patterns embedding version and victim information, and it presents ransom instructions by changing the desktop wallpaper. Some variants imposed short response deadlines and instructed victims to contact the operators by email to negotiate payment. In reported cases, operators supplied a decryptor and victim-specific key material after payment.
Cryakl has been distributed primarily through email-based social engineering. Observed delivery methods include phishing and malspam campaigns impersonating trusted institutions such as courts or local organizations, with lures claiming legal or administrative action. Attachments and linked payloads have included malicious Office documents with macros, JavaScript downloaders, PDFs leading to executable downloads, and archive-contained droppers. At least one campaign used a dropper to install both Cryakl and a password-stealing trojan, indicating combined monetization through ransomware and credential theft.
On infected systems, Cryakl establishes persistence through Windows autorun mechanisms and stores local state so encryption can resume after reboot. Variants have transmitted victim and keying information to attacker infrastructure using SMTP in earlier versions and HTTP POST in later ones. The family has also been associated with partner-based distribution resembling a ransomware-as-a-service model, with operators supplying builds to affiliates targeting additional regions beyond Russia.
Cryakl remained difficult to decrypt for years because of its asymmetric cryptography design. Later law-enforcement seizure of attacker infrastructure yielded private keys that enabled decryption support for several versions through public recovery tooling, significantly reducing the impact of some historical variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Update - 12/02 : thanks to a tweet from Catalin this appears to be another version of so called "offline" ransomware, discovered by Check Point: “Offline” Ransomware Encrypts Your Data without C&C Communication
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family known for encrypting files and demanding payment, also referred to as CryLock.
Ransomware family that uses a filename pattern containing email, version, ID, random name, and a random extension.
Cryakl is a Delphi-written ransomware/cryptor that spread primarily via spam emails with malicious attachments, encrypted victim files, changed desktop wallpaper in some variants, and demanded Bitcoin payment in exchange for a decryptor and key file. Later versions used RSA to protect decryption data and supported a partner/RaaS-style distribution model.
Named as the ransomware family/variant that Vipasana belongs to; the content indicates Vipasana is a Cryakl variant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.