Kraken Cryptor is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on August 1, 2018, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: KrakenCryptor.
Quick Facts
Ransomware Family
Kraken Cryptor
First Seen
August 1, 2018
Known Aliases
KrakenCryptor
How Kraken Cryptor Ransomware Works
Targeted Files
Check for date (in ticks https://tickstodatetime.azurewebsites.net/). (To success start set date to start of 2018)
Renames files
https://www.bleepingcomputer.com/news/security/kraken-cryptor-ransomware-masquerading-as-superantispyware-security-program/
File Encryption Patterns
Kraken Cryptor modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..onion./\.[A-Z0-9]{5}$/
Ransom Note and Payment Demands
After encrypting files, Kraken Cryptor displays ransom notes demanding payment for file recovery:
file# How to Decrypt Files.txt
Ransom message:
notes/# How to Decrypt Files.txt
Note locations:
EveryFolder
file# How to Decrypt Files.html
Ransom message:
notes/# How to Decrypt Files.html
Note locations:
EveryFolder
file/^# How to Decrypt Files-[A-Z0-9]{5}\.html$/
Ransom message:
notes/# How to Decrypt Files-ICDZ4.html
Note locations:
EveryFolder
file/^Instructions-[A-Z0-9]{5}\.html$/
Ransom message:
notes/Instructions-PTFON.html
Note locations:
EveryFolder
screenshot
Ransom message:
notes/wallpaper.png
Note locations:
Desktop
Technical Indicators
Associated Executable Files
The following executable files are associated with Kraken Cryptor ransomware:
Kraken.exe
kraken.exe
KrakenCryptor.exe
auService.exe
krakenc.exe
file.exe
myfile.exe
SUPERAntiSpywares.exe
Main.exe
Yandex.exe
UAC.exe
partmgr.sys
Kraken.bin
2018-10-04_19-37-40.bin
2018-10-04_19-37-40.exe
Elastio Can Help You
Don't let Kraken Cryptor ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
This Kraken Cryptor ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Kraken Cryptor.