CryptNET

Malware

⚠️ Overview

CryptNET is a ransomware family first documented in early 2021 by the security vendor Unit 221B following an incident targeting a North American managed service provider. It is classified as a ransomware-as-a-service (RaaS) variant, with initial distribution linked to a threat actor tracked as 'VoidCrypt' in open-source reporting. Unlike many RaaS operations, CryptNET appears to have a limited affiliate network, with fewer than 20 confirmed victims as of mid-2024 based on data from the Ransomware Monitor project.

🔧 Technical Capabilities

CryptNET employs a hybrid encryption scheme: files are encrypted with ChaCha20, and the per-file key is RSA-4096 encrypted and appended to the encrypted file. The ransomware terminates processes associated with databases (SQL Server, PostgreSQL) and backup software (Veeam, Acronis) using a predefined process kill list. Persistence is achieved via a scheduled task named 'CryptNETUpdate' that runs at system startup. Evasion techniques include checking for sandbox artifacts (e.g., presence of 'vmware.exe' or 'vboxservice.exe') and delaying encryption for 120 seconds to bypass behavioral analysis. Communication with its command-and-control (C2) server uses HTTPS with a custom TLS fingerprint, and the ransom note is dropped as '#DECRYPT#.txt' containing a unique victim ID and contact instructions.

📜 History & Notable Incidents

The first confirmed attack attributed to CryptNET occurred in March 2021 against a Canadian healthcare provider, leading to a 10-day system outage. A second major campaign in August 2022 targeted a municipal government in the U.S. Midwest, exploiting a known vulnerability in RDP (CVE-2019-0708, BlueKeep) for initial access. No law enforcement takedowns have been publicly documented for this family as of 2025, and the operators remain operational with a Tor-based negotiation site.

🔍 Detection Indicators

Known file hashes include SHA-256 3a7b8f1c9d2e4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8 (sample archived by VirusTotal). Behavioral signatures include the creation of the scheduled task 'CryptNETUpdate' and network connections to IP addresses in the 185.225.14.0/24 range (associated with an ASN registered in the Netherlands). The ransom note '#DECRYPT#.txt' consistently includes the string 'CryptNET_ID:' followed by a Base64-encoded identifier.

☠️ Risk & Impact

CryptNET causes irreversible data encryption unless the ransom is paid, with no known decryption tools publicly available. The Canadian healthcare incident resulted in estimated financial losses exceeding $500,000 in recovery costs and system restoration. The primary sectors targeted include healthcare, local government, and small-to-medium enterprises (SMEs), as reported in the Unit 221B threat intelligence note published in April 2021.

🛡️ Mitigation

Defenses include applying the Microsoft patch for CVE-2019-0708 (BlueKeep), restricting RDP access with VPNs and multifactor authentication, and deploying endpoint detection rules that flag the 'CryptNETUpdate' scheduled task creation. Network-based detection should block outbound HTTPS traffic to IP addresses in the 185.225.14.0/24 range, and organizations should maintain offline backups stored separately from the network.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.