CryptNET is a ransomware family first documented in early 2021 by the security vendor Unit 221B following an incident targeting a North American managed service provider. It is classified as a ransomware-as-a-service (RaaS) variant, with initial distribution linked to a threat actor tracked as 'VoidCrypt' in open-source reporting. Unlike many RaaS operations, CryptNET appears to have a limited affiliate network, with fewer than 20 confirmed victims as of mid-2024 based on data from the Ransomware Monitor project.
CryptNET employs a hybrid encryption scheme: files are encrypted with ChaCha20, and the per-file key is RSA-4096 encrypted and appended to the encrypted file. The ransomware terminates processes associated with databases (SQL Server, PostgreSQL) and backup software (Veeam, Acronis) using a predefined process kill list. Persistence is achieved via a scheduled task named 'CryptNETUpdate' that runs at system startup. Evasion techniques include checking for sandbox artifacts (e.g., presence of 'vmware.exe' or 'vboxservice.exe') and delaying encryption for 120 seconds to bypass behavioral analysis. Communication with its command-and-control (C2) server uses HTTPS with a custom TLS fingerprint, and the ransom note is dropped as '#DECRYPT#.txt' containing a unique victim ID and contact instructions.
The first confirmed attack attributed to CryptNET occurred in March 2021 against a Canadian healthcare provider, leading to a 10-day system outage. A second major campaign in August 2022 targeted a municipal government in the U.S. Midwest, exploiting a known vulnerability in RDP (CVE-2019-0708, BlueKeep) for initial access. No law enforcement takedowns have been publicly documented for this family as of 2025, and the operators remain operational with a Tor-based negotiation site.
Known file hashes include SHA-256 3a7b8f1c9d2e4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8 (sample archived by VirusTotal). Behavioral signatures include the creation of the scheduled task 'CryptNETUpdate' and network connections to IP addresses in the 185.225.14.0/24 range (associated with an ASN registered in the Netherlands). The ransom note '#DECRYPT#.txt' consistently includes the string 'CryptNET_ID:' followed by a Base64-encoded identifier.
CryptNET causes irreversible data encryption unless the ransom is paid, with no known decryption tools publicly available. The Canadian healthcare incident resulted in estimated financial losses exceeding $500,000 in recovery costs and system restoration. The primary sectors targeted include healthcare, local government, and small-to-medium enterprises (SMEs), as reported in the Unit 221B threat intelligence note published in April 2021.
Defenses include applying the Microsoft patch for CVE-2019-0708 (BlueKeep), restricting RDP access with VPNs and multifactor authentication, and deploying endpoint detection rules that flag the 'CryptNETUpdate' scheduled task creation. Network-based detection should block outbound HTTPS traffic to IP addresses in the 185.225.14.0/24 range, and organizations should maintain offline backups stored separately from the network.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.