DisclosureLens
← All groups

crosslock

Active since 2023-04-17
1 claimed victims

Unverified threat-actor claim — not a regulatory filing

Attribution, victim identity, and counts shown here derive from crosslock's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

According to ransomware.live, the group claims:

CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil.

Source: Ransomware.live

Crosslock ransomware group · DisclosureLens