PULSE NAME
Kryptina RaaS - From Unsellable Cast-Off to Enterprise Ransomware
WHITE Mallox AlienVault 2024-09-24 Modified: 2024-10-24
75
IOCs
HIGH VOLUME
This analysis examines the evolution of Kryptina, a ransomware-as-a-service platform, from a free tool on public forums to being actively used in enterprise attacks under the Mallox ransomware family. In May 2024, a Mallox affiliate leaked staging server data, revealing their Linux ransomware was based on a modified version of Kryptina. The affiliate made superficial changes to source code and documentation, removing Kryptina branding but retaining core functionality. This adoption exemplifies the commoditization of ransomware tools, complicating malware tracking as affiliates blend different codebases into new variants. The report details the similarities and differences between the original Kryptina RaaS and the modified Mallox version, including encryption methods, ransom note templates, and configuration files.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Kryptina Mallox
Indicators of Compromise (18 / 75 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 CVE domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 71efe7a21da183c407682261612afc0f 2024-09-24
FileHash-MD5 1448ce8abc2f0184ec898d55f9c338b4 2024-09-24
FileHash-MD5 193d2c42fea21defedbce498b5039272 2024-09-24
FileHash-MD5 231478ff24055d5cdb5fbec36060c8ff 2024-09-24
FileHash-MD5 4825f3a92780be4a285583b0f24fed99 2024-09-24
FileHash-MD5 51d51696c7f3a0e3fba4b8ceab210bac 2024-09-24
FileHash-MD5 5b0c1958a875c205951b88fd1c885900 2024-09-24
FileHash-MD5 68785d476573955d50a3908dc18bf73b 2024-09-24
FileHash-MD5 6bb2752ea73b4d6a5c33f543b5c29461 2024-09-24
FileHash-MD5 779aa15cd6a8d416e7f722331d87f47b 2024-09-24
FileHash-MD5 7f099845d8e6849d6ab4d64b546477d6 2024-09-24
FileHash-MD5 846bb4f2cdbf9ed624ba2647c6b04101 2024-09-24
FileHash-MD5 8d0fd41d35df82d3e7e2ff5c1747b87c 2024-09-24
FileHash-MD5 af1d24091758f1e02d51dc5f5297c932 2024-09-24
FileHash-MD5 b0770b7f24a436d256f2d58fc8581a18 2024-09-24
FileHash-MD5 b5b20e03ae941e9f21c444bd50225c41 2024-09-24
FileHash-MD5 be08c3e95df5992903a69e04cbab22e3 2024-09-24
FileHash-MD5 e9e087c52b97c7a3e343642379829e0a 2024-09-24