Back to Threat Groups
crosslock
INACTIVEransomware group
CrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion approach—encrypting data and threatening to leak it publicly. Written in Go, it uses a hybrid encryption scheme combining ChaCha20 for file encryption with Curve25519 for key protection. Victims see their files renamed with the .crlk extension and ransom notes titled ---CrossLock_readme_To_Decrypt---.txt. The malware includes advanced techniques like Event Tracing for Windows (ETW) bypass and process mimicking (e.g., Cybereason processes) for stealth. It was publicly tracked until July 2023, after which activity (and its leak site) went offline.
Victims
1
records
First Discovered
Apr 17, 2023
victim
Last Discovered
Apr 17, 2023
victim
Inactive Since
1,166
days
Countries
1
hit
Avg Discount
—
no settlements
Group Activity
Last 12 monthsJul
2025
Aug
2025
Sep
2025
Oct
2025
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026
Jun
2026
Infrastructure
No sites tracked