Crucio is a Windows destructive malware family that presents as ransomware but functions as a wiper. It encrypts victim files, appends a distinctive extension, and may alter the desktop wallpaper with threatening messaging, but it does not preserve the encryption material needed for recovery and does not provide a genuine ransom-and-decryption workflow. Because the randomly generated keys and initialization vectors are intentionally discarded, affected files cannot be decrypted, making the malware operationally destructive rather than extortion-driven.
Crucio is notable both as a standalone destructive family and as a code lineage reused in later tooling. Microsoft linked a fake-ransomware module inside the modular backdoor GigaWiper to Crucio based on shared encryption logic and function structure, indicating that Crucio’s file-destruction routine was incorporated into a broader post-compromise platform. Reporting has also associated Crucio with activity affecting Israeli organizations, and broader public discussion has connected related tooling to Iran-nexus operations, although attribution should be treated cautiously where not explicitly confirmed.
The malware targets Windows environments and is relevant to destructive intrusion scenarios in which attackers already possess access and seek to sabotage systems, impede recovery, or disguise destructive intent as conventional ransomware. Its core behavior is irreversible file encryption without a viable recovery path, aligning it more closely with wiper tradecraft than with financially motivated ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Fake ransomware built on older code called Crucio. It encrypts files, adds a .candy extension, and changes the desktop wallpaper to an alarming warning image. There is no ransom note and no saved key, so there is nothing to pay and nothing to decrypt.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware generates random AES encryption keys and initialization vectors that are intentionally discarded after encryption. Unlike conventional ransomware operations, no mechanism exists for recovering encrypted files because the encryption material is never retained.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously separate malware family whose file encryption routines were incorporated into GigaWiper's unified framework.
A ransomware family whose code was reused in GigaWiper's fake ransomware component.
Шифровальщик, код которого использован в одном из модулей GigaWiper для необратимого уничтожения данных: файлы шифруются, получают расширение .candy, при этом ключ не сохраняется и записка о выкупе не оставляется.
A ransomware family from which GigaWiper's fake ransomware module is derived; in this context it is used as the basis for irreversible file encryption by discarding the keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.