Researchers detailed Cyrat, a Python-based ransomware strain that masqueraded as a DLL repair tool and primarily targeted English-speaking users while remaining capable of wider global spread. After execution, the malware encrypted files in common user directories, appended the .CYRAT extension, and dropped RANSOME_NOTE.txt ransom notes demanding $1,000 in Bitcoin, with a reduced $500 payment offer if victims paid within two days.
Technical analysis found that Cyrat used Fernet symmetric encryption via PyCryptodome to encrypt entire files, then protected the Fernet key with an RSA public key downloaded from MediaFire rather than embedding it in the sample. The encrypted key was stored in EMAIL_US.txt for victims to send back to the attackers, and the malware also downloaded an image, saved it as background_img.png, and changed the desktop wallpaper to draw attention. Researchers noted Cyrat had relatively low prevalence and contained coding flaws, including extension-matching issues and a reported Pyfiglet-related crash that could disrupt encryption.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A Cyrat ransom note referenced a payment deadline of Aug-27-2020 and demanded $1,000 in Bitcoin, with a reduced $500 payment if paid within two days. Victims were instructed to contact officialintuitsoftware@gmail.com and send EMAIL_US.txt.
The Cyrat ransomware family was observed active in the second half of August 2020. It is described as a Python-based ransomware targeting primarily English-speaking users while capable of spreading globally.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.