crosslock

Ransomware
Origin🇧🇷 Brasil
Sourceransomware.live

About the group

CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group crosslock has 1 known ransomware victims. See the most affected sectors and countries and recent victims.

1known victims
1in Brazil
1sectors hit
Most attacked sectors
Agriculture and Food Production1
Most affected countries
🇧🇷 Brasil1
Recent victims
validcertificadora.com.brAgriculture and Food Production · BR · 2023-04-17

crosslock uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →