Ransomware Research

CryptoCat Ransomware

CryptoCat is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on September 1, 2016, this ransomware has been actively targeting systems worldwide.

Quick Facts

Ransomware Family
CryptoCat
First Seen
September 1, 2016

How CryptoCat Ransomware Works

Targeted Files

NOSAMPLE

File Encryption Patterns

CryptoCat modifies encrypted files using specific patterns to mark them as encrypted:

File extensions added after encryption:

..cryptocat

Ransom Note and Payment Demands

After encrypting files, CryptoCat displays ransom notes demanding payment for file recovery:

fileYour files are locked !.txt

Ransom message:

notes/Your files are locked !.txt

Elastio Can Help You

Don't let CryptoCat ransomware take over your data

Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.

About This Analysis

This CryptoCat ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like CryptoCat.

Last updated: July 30, 2025