CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil. Known victims: 1
Objectives
Executive Summary
CrossLock is a short-lived ransomware group that emerged in April 2023 and disappeared by July 2023. The group uses Go-based ransomware with Curve25519 and ChaCha20 encryption, employing double-extortion tactics. Targeting primarily the IT sector in Brazil, CrossLock has only one confirmed victim to date.
Goals & Targeting
CrossLock operates with the primary goals of financial gain through ransom payments and organizational disruption. The group targets sectors where ransoms are likely to be paid, such as businesses with high data sensitivity or critical operations. Its targeting focus on Brazil suggests either a regional operational capacity or an attempt to exploit specific geographic vulnerabilities. CrossLock's double-extortion tactics indicate a strategic focus on maximizing the psychological impact and financial incentive for victims. The group’s limited activity window (April-July 2023) suggests either early-stage development challenges or external pressures that curtailed their operations.
Enhanced Description
CrossLock is a newly identified ransomware group that surfaced in April 2023 and was reported inactive by July 2023. The group's operational window was short but impactful, utilizing advanced encryption methods (Curve25519 and ChaCha20) to secure their payloads and employing double-extortion tactics—exfiltrating victim data before encrypting systems. This approach combines traditional ransom demands with the threat of data leaks, a common strategy among modern ransomware groups. Despite its brief activity, CrossLock demonstrates a technical proficiency in encryption and operational tradecraft. The group's targeting focus appears to be on IT sector organizations within Brazil, suggesting either a regional interest or limited operational capacity. CrossLock's rapid rise and fall indicate potential challenges in scaling their operations or maintaining long-term persistence. While the group remains low-profile due to its short lifespan, it is notable for its technical implementation and adherence to emerging ransomware trends.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CrossLock’s campaign activity appears to have been concentrated between April and July 2023, with minimal confirmed victims. The group's rapid emergence and disappearance suggest either a highly specialized operational approach or challenges in maintaining long-term campaigns. Despite its short lifespan, CrossLock demonstrates technical sophistication in encryption methods and double-extortion tactics. Notably, the group did not appear to engage in widespread targeting beyond their single confirmed victim, indicating possible focus on high-value targets within specific sectors or geographies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in CrossLock's threat intelligence due to limited reporting and a single confirmed victim. The group’s brief operational window and lack of detailed TTPs make comprehensive analysis challenging. Data gaps include the full scope of their targeting, geographic reach beyond Brazil, and potential association with other ransomware groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics