Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors crosslock

Description

CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil. Known victims: 1

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

CrossLock is a short-lived ransomware group that emerged in April 2023 and disappeared by July 2023. The group uses Go-based ransomware with Curve25519 and ChaCha20 encryption, employing double-extortion tactics. Targeting primarily the IT sector in Brazil, CrossLock has only one confirmed victim to date.

Goals & Targeting

CrossLock operates with the primary goals of financial gain through ransom payments and organizational disruption. The group targets sectors where ransoms are likely to be paid, such as businesses with high data sensitivity or critical operations. Its targeting focus on Brazil suggests either a regional operational capacity or an attempt to exploit specific geographic vulnerabilities. CrossLock's double-extortion tactics indicate a strategic focus on maximizing the psychological impact and financial incentive for victims. The group’s limited activity window (April-July 2023) suggests either early-stage development challenges or external pressures that curtailed their operations.

Enhanced Description

CrossLock is a newly identified ransomware group that surfaced in April 2023 and was reported inactive by July 2023. The group's operational window was short but impactful, utilizing advanced encryption methods (Curve25519 and ChaCha20) to secure their payloads and employing double-extortion tactics—exfiltrating victim data before encrypting systems. This approach combines traditional ransom demands with the threat of data leaks, a common strategy among modern ransomware groups. Despite its brief activity, CrossLock demonstrates a technical proficiency in encryption and operational tradecraft. The group's targeting focus appears to be on IT sector organizations within Brazil, suggesting either a regional interest or limited operational capacity. CrossLock's rapid rise and fall indicate potential challenges in scaling their operations or maintaining long-term persistence. While the group remains low-profile due to its short lifespan, it is notable for its technical implementation and adherence to emerging ransomware trends.

Key Capabilities

  • Go-based ransomware implementation
  • Curve25519 encryption algorithm
  • ChaCha20 encryption algorithm
  • Double-extortion tactics (exfiltration + encryption)
  • Limited operational window with high technical focus

MITRE ATT&CK Tactics

Ransomware
Data Breach
Exfiltration
Impact/Interruption

ATT&CK Techniques

T1070.001
T1055
T1078
T1566.002

Software / Tooling

Go-based ransomware (specific toolset not named)
Curve25519 encryption implementation
ChaCha20 encryption implementation

Campaigns & Victims

CrossLock’s campaign activity appears to have been concentrated between April and July 2023, with minimal confirmed victims. The group's rapid emergence and disappearance suggest either a highly specialized operational approach or challenges in maintaining long-term campaigns. Despite its short lifespan, CrossLock demonstrates technical sophistication in encryption methods and double-extortion tactics. Notably, the group did not appear to engage in widespread targeting beyond their single confirmed victim, indicating possible focus on high-value targets within specific sectors or geographies.

IOC Patterns

  • Go-based malware signatures associated with ransomware activity
  • Network traffic anomalies using Curve25519 encryption
  • Double-extortion patterns (data exfiltration + encryption)
  • Limited targeting in the IT sector of Brazil

Recommended Actions

  • Enhance endpoint detection to identify Go-based malware and suspicious process creations.
  • Implement network monitoring for encryption-based anomalies using Curve25519 or ChaCha20 algorithms.
  • Strengthen incident response capabilities to detect and mitigate double-extortion activities.
  • Conduct regular employee training on phishing and suspicious email protocols.
  • Ensure robust backups of critical data systems to mitigate ransomware impacts.

Suggested Tags

Ransomware
Double extortion
Encryption-based threats
Latin America
IT sector

Confidence Assessment

Low confidence in CrossLock's threat intelligence due to limited reporting and a single confirmed victim. The group’s brief operational window and lack of detailed TTPs make comprehensive analysis challenging. Data gaps include the full scope of their targeting, geographic reach beyond Brazil, and potential association with other ransomware groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Double extortion
Encryption-based threats
Latin America
IT sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 17, 2023
Last Seen
Apr 17, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.