Back to Threat Groups

cryptnet

INACTIVE

ransomware group

CryptNet is a newer Ransomware-as-a-Service (RaaS) operation first identified in April 2023. It follows a double-extortion model, performing data exfiltration before encrypting files. Written in .NET and obfuscated with .NET Reactor, CryptNet utilizes AES-256 (CBC) and RSA-2048 encryption. Its codebase shares strong similarities with Chaos and Yashma ransomware families.

Victims
2
records
First Discovered
Apr 19, 2023
victim
Last Discovered
Apr 19, 2023
victim
Inactive Since
1,259
days
Countries
0
hit
Avg Discount
—
no settlements

Group Activity

Last 12 months
Oct
2025
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026
Jun
2026
Jul
2026
Aug
2026
Sep
2026