Researchers identified CryptoHost, also tracked as Manamecrypt, as a ransomware family that did not truly encrypt files but instead moved targeted data into a password-protected RAR archive and demanded 0.33 Bitcoin for recovery. The malware reportedly stored both the archive and its executable under AppData\Roaming, established persistence through a Run registry key, and verified exact ransom payments through blockchain.info before releasing files. It was also reported as being bundled with a uTorrent installer and detected by security products as Ransom:MSIL/Manamecrypt.A and Ransom_CRYPTOHOST.A.
Analysis of the malware showed the archive password was generated predictably from the archive name and the victim username, allowing affected files to be recovered without paying the ransom. Researchers also said the threat attempted to frustrate remediation by deleting the SafeBoot registry key and terminating processes associated with security tools, administration, gaming, shopping, and social-media applications. While some reports described the attacks as highly disruptive for users and companies, they also warned that ransom payment via Bitcoin remained risky and offered no guarantee of successful recovery, reinforcing the need for preventive security controls and backups.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Later reporting on Manamecrypt, also referred to as CryptoHost, stated that files from the current attacks could be decrypted and warned that paying the ransom in Bitcoin did not guarantee recovery. The report also noted investigators had not prominently observed the malware using a backdoor.
Observed infections showed CryptoHost being distributed through a bundled uTorrent installer that dropped cryptohost.exe into the victim's AppData folder and executed it. The malware then demanded 0.33 bitcoin for file recovery.
Security researcher Jack identified a new ransomware family called CryptoHost that did not truly encrypt files, but instead moved them into a password-protected RAR archive with a predictable password, making recovery possible without paying. Additional analysis was credited to Michael Gillespie and MalwareHunterTeam.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.