crosslock
First seen April 17, 2023Active1 claimed victims
The claims below are reproduced as posted by crosslock on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| validcertificadora.com.br | April 17, 2023 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).