Skip to main content

Operator dossier

Crosslock is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 1 public victims claimed by this operator between April 17, 2023. Crosslock is an obscure ransomware group that emerged in April 2023, appearing to be financially motivated based on typical ransomware group patterns. The group's country of origin and operational structure remain unknown due to limited public documentation from major threat intelligence sources. Based on available data, the group has demonstrated minimal operational scale with only one documented victim, suggesting either highly targeted operations or limited operational capacity. The group appears to focus its targeting efforts primarily on Brazilian entities, though the specific attack methodology, encryption techniques, and extortion tactics employed by Crosslock have not been publicly documented by major cybersecurity firms or law enforcement agencies. No major campaigns, high-profile victims, or significant ransoms have been publicly attributed to this group by reputable sources. The current operational status of Crosslock remains unclear due to the limited threat intelligence available on this group.

Most-affected countries

Recent disclosures by Crosslock

All 1 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Crosslock

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

Crosslock

1 victims indexed · first seen 3 years ago · last activity 3 years ago

1
Victims indexed
#323 of 370 tracked operators
<1m
Active period
Apr 2023 → Apr 2023
1
Countries hit
top Brazil · 1

At a glance

Status
inactive
First seen
3 years ago
Last activity
3 years ago
Onion sites
1 known endpoint

About

Crosslock is an obscure ransomware group that emerged in April 2023, appearing to be financially motivated based on typical ransomware group patterns. The group's country of origin and operational structure remain unknown due to limited public documentation from major threat intelligence sources. Based on available data, the group has demonstrated minimal operational scale with only one documented victim, suggesting either highly targeted operations or limited operational capacity. The group appears to focus its targeting efforts primarily on Brazilian entities, though the specific attack methodology, encryption techniques, and extortion tactics employed by Crosslock have not been publicly documented by major cybersecurity firms or law enforcement agencies. No major campaigns, high-profile victims, or significant ransoms have been publicly attributed to this group by reputable sources. The current operational status of Crosslock remains unclear due to the limited threat intelligence available on this group.

References

6 links

External sources curated by the MISP threat-intel community.

Timeline

1 months
2023-04-01T00:00:00+00:00 · 1
2023-04-01T00:00:00+00:002023-04-01T00:00:00+00:00

Top countries

🇧🇷 Brazil
1

MITRE ATT&CK

3 techniques · 3 tactics

Tactics

Initial AccessExecutionImpact

Techniques

  • T1566Phishing
  • T1059Command and Scripting Interpreter
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

1 known
  • http://crosslock5cwfljbw4v37zuzq4talxxhyavjm2lufmjwgbpfjdsh56yd.onion

Source

Updated 3 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Crosslock posts a victim.

Add Crosslock to your watchlist — Pro pings you within 5 minutes of any new Crosslock leak-site post, Telegram callout, or affiliate-rebrand inference.