Skip to main content
Ransomware Group

Crylock

CryLock (originally known as Cryakl/Fantomas since 2014) is a ransomware operation run by a Russian couple who targeted roughly 400,000 victims over eight years and earned over €64 million in Bitcoin; the operators were arrested in Spain in June 2023 and extradited to Belgium.

Known victims0

Threat Level

LOW

Known Infrastructure

The following Tor hidden services have been associated with this group:

  • d57uremugxjrafyg.onion

Warning: These are malicious sites. Do not visit without proper security measures.

0

Check If You’re Affected

Search our database to see if your organization appears in Crylock’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request