blackbyte-crux
ACTIVEransomware group
Crux is a newly identified ransomware variant active since July 2025, which claims affiliation with the established BlackByte ransomware group. It implements a double‑extortion model—encrypting files (with the .crux extension) and threatening data leak via a Tor-based portal. A distinctive feature of Crux is its execution flow: it initiates via svchost.exe, cmd.exe, and bcdedit.exe to disable Windows recovery, followed by rapid file encryption. The ransomware has been confirmed in at least three incidents across sectors including agriculture, education, professional services, media, and nonprofits, in both the U.S. and U.K. Ransom notes consistently follow the naming pattern crux_readme_[random].txt.
1
Nov 17, 2025
Apr 13, 2026
Victims (0)
No victims recorded
Infrastructure
http://dounczge5jhw4iztnnpzp54kd4ot3tikhjsimurtcewqssgye6vvrhqd.onion/61124ms
1h ago
http://faow6n2hkweyyalp67zvonafn2dzphw36cav653wamj724mwsmtfa5yd.onion/2583ms
1h ago