Cryxos is a family of malicious JavaScript trojans primarily associated with fraudulent alert and tech-support scam activity. It typically presents fake security warnings or infection alerts in web pages or script-based lures to pressure victims into calling attacker-controlled numbers or following further social-engineering steps. In observed intrusion chains, Cryxos-themed content has been embedded in HTML or JavaScript files and used to impersonate trusted organizations or contextually relevant entities, including government and business-related themes.
Cryxos activity is linked to social-engineering operations that can lead victims to grant remote access, install additional software, or expose sensitive information. Reported downstream outcomes include installation of remote-access tools or other malware, credential theft, and potential enablement of ransomware deployment. Some detections also associate Cryxos-labeled JavaScript samples with broader credential-theft activity, including AgentTesla-related delivery chains, indicating that the Cryxos label may at times apply to obfuscated script droppers used to stage additional payloads rather than only classic browser-based scam pages.
Cryxos has been observed in malicious attachments and web-hosted lures, including spearphishing-style delivery using business-themed documents and organization-themed decoys. On Windows, Cryxos-attributed scripts have been seen executing through Windows Script Host, decoding embedded payloads, invoking PowerShell for in-memory execution, dropping additional binaries, and establishing persistence through autorun mechanisms. Separate JavaScript samples attributed to Cryxos have also demonstrated infostealer behavior in Linux environments, including explicit detection of Windows Subsystem for Linux and attempts to enumerate Windows user context and browser-related paths through mounted host filesystems.
The malware family has appeared in investigations involving social engineering against public-sector organizations and in broader ransomware-adjacent contexts where credential theft or remote-access enablement may have contributed to later compromise stages. Targeting reflected in observed lures includes county and city government personnel as well as manufacturing, logistics, and procurement staff. Cryxos is best characterized as a JavaScript trojan family used for deceptive user interaction and, in some cases, as a staging mechanism for follow-on malware and information theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors often use Wacatac to steal information... by using JavaScript injected into a vulnerable website to display messages leading to downloads of it.
The notification highlights four recent incidents that affected county governments and identifies phishing, remote desktop protocol (RDP) compromise, and exploitation of vulnerable software as the three most common means by which threat actors initially accessed victims’ systems.
The script decodes multiple layers of obfuscation... 5-layer string obfuscation, Unicode obfuscation
The data collected and analyzed thus far has led researchers to hypothesize that the incident may have begun with social engineering... the appearance of the county government domains in files linked to the Cryxos trojan, which enables such activity, may support the hypothesis that county personnel fell victim to social engineering in the early stages of the attack. | These files typically enable tech support scams: they warn the user that their computer has been infected by a virus and direct them to call a threat actor-controlled telephone number.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryxos is a family of malicious JavaScript files that displays fraudulent alerts and directs victims to call attacker-controlled phone numbers. The content links it to callback-phishing-like behavior that can facilitate remote access, theft, or installation of additional malware including ransomware.
A family of malicious JavaScript files used in tech support scam activity. It displays fake infection alerts, prompts victims to call attacker-controlled phone numbers, and can be used to socially engineer victims into installing remote-access software or RATs, potentially enabling initial access.
A family of malicious JavaScript files used in fake alert and tech-support scam activity; in some cases it can lead victims to install remote-access software that facilitates data theft or ransomware deployment.
An obfuscated JScript crypter/dropper family used to deliver credential-theft payloads such as AgentTesla, employing heavy string obfuscation, payload inflation, PowerShell execution, dropped binaries disguised as .png files, and Run-key persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.