Back to Threat Groups

blackbyte-crux

ACTIVE

ransomware group

Crux is a newly identified ransomware variant active since July 2025, which claims affiliation with the established BlackByte ransomware group. It implements a double‑extortion model—encrypting files (with the .crux extension) and threatening data leak via a Tor-based portal. A distinctive feature of Crux is its execution flow: it initiates via svchost.exe, cmd.exe, and bcdedit.exe to disable Windows recovery, followed by rapid file encryption. The ransomware has been confirmed in at least three incidents across sectors including agriculture, education, professional services, media, and nonprofits, in both the U.S. and U.K. Ransom notes consistently follow the naming pattern crux_readme_[random].txt.

Victims

1

First Seen

Nov 17, 2025

Last Active

Apr 13, 2026

Victims (0)

No victims recorded

Infrastructure

leak site
ONLINE
http://dounczge5jhw4iztnnpzp54kd4ot3tikhjsimurtcewqssgye6vvrhqd.onion/

61124ms

1h ago

leak site
OFFLINE
http://faow6n2hkweyyalp67zvonafn2dzphw36cav653wamj724mwsmtfa5yd.onion/

2583ms

1h ago