The Cryakl ransomware family, also known as Fantomas, Crykal, and later CryLock, developed from early spam-driven attacks into a broader ransomware operation that encrypted files without needing live command-and-control communication and increasingly relied on affiliate-style distribution. Early campaigns targeted victims primarily in Russia, with additional activity in Germany, Kazakhstan, Ukraine, Belarus, Japan, and Italy, using phishing emails and malicious archives to deliver Delphi-based malware that encrypted portions of files, stored metadata locally, persisted through Windows registry keys, and in some cases installed the password-stealing trojan Trojan-PSW.Win32.Ruftar alongside the ransomware. Researchers also documented versions that used layered encryption with locally generated keys and hardcoded remote RSA public keys, allowing attackers to extort victims without any online key exchange.
The operation later adopted tactics associated with modern double extortion. Deutsche Telekom linked at least one intrusion to a CryLock affiliate that encrypted a victim environment, displayed a pre-login legal warning, and threatened to publish stolen data through the LOCKDATA Auction leak marketplace, underscoring the shift from pure encryption to data-theft coercion. Separately, Belgian police seized Cryakl command-and-control servers and obtained private keys that enabled Kaspersky to expand decryption support in RakhniDecryptor, helping victims recover files from several Cryakl variants and disrupting one of the more prominent ransomware families active in Russia.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
Deutsche Telekom Security said LOCKDATA Auction had been known to it since May 2021. The portal advertised auctions of stolen victim data and appeared to support ransomware-related extortion.
In early February, Belgian police seized Cryakl command-and-control servers. The seizure later enabled recovery of private keys used to support decryption for several Cryakl versions.
Deutsche Telekom reported that Crykal was rebranded as CryLock in 2020. The family continued operating under a ransomware-as-a-service model with affiliates deploying the malware.
Deutsche Telekom stated that Crykal infrastructure was taken down in 2018 and that a decryptor was subsequently published. This marked a disruption of the earlier Crykal operation before its later rebranding.
Kaspersky observed a 2016 Cryakl modification distributed as a script for a popular Russian accounting program and a business process management tool. The lure told employees to update the bank classifier by opening an attached executable file.
Check Point found that between March and April 2015, the ransomware's file version schema changed by adding a CL prefix and restarting version numbers. Around April 2015, the encrypted file naming format also changed from retaining original filenames to using random filenames.
Kaspersky reported that Trojan-Ransom.Win32.Cryakl.bo was detected in October and delivered through a phishing campaign using a redirected link to download Attachment.zip. The dropper installed both Cryakl and the Ruftar password stealer, while the ransomware sent victim data to attacker infrastructure via HTTP POST.
On September 22, attackers distributed the Trojan-Ransom.Win32.Cryakl.ax variant to nearly 500 users within a single hour. This was highlighted as part of the late-September Cryakl spam wave.
Kaspersky reported that Cryakl infection attempts peaked in the last week of September at nearly 600 attacks per day, with most activity in Russia and additional victims in Germany, Kazakhstan, Ukraine, and Belarus. The campaigns used phishing emails impersonating the Supreme Arbitration Court of the Russian Federation.
Check Point reported that the first reported reference to this ransomware family appeared in June 2014. The family would later be associated with Cryakl/CryLock lineage in other reporting.
Kaspersky stated that the first Cryakl family sample was added to its databases on April 29, marking the early documented appearance of the ransomware family later also called Fantomas. Other references describe Cryakl's first observed attacks as occurring in 2014.
Deutsche Telekom investigated a case in which a CryLock affiliate encrypted a victim environment and displayed a startup legal notice threatening sale of stolen files. The notice referenced a Tor address associated with LOCKDATA Auction and linked to Search_keys_CryLOCK_3.0.exe hosted on a cloud provider.
After receiving Cryakl private keys from Belgian police, Kaspersky updated its free RakhniDecryptor tool. The update enabled recovery of files encrypted by several Cryakl ransomware versions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
telekom.com
Open sourcesecurelist.com
Open sourceblog.checkpoint.com
Open sourcesecurelist.ru
Open sourcevirusinfo.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.