Ransomware Group intelligence
Cryptowall
InactiveTrack Cryptowall with 4 published victims in a single intelligence view.
Overview
Cryptowall is tracked by Breach House as a ransomware group with 4 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (2)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Cryptowall, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: cryptowall executes PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: cryptowall leverages native API calls to bypass detection while executing core ransomware functions.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: cryptowall modifies registry run keys to ensure persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: cryptowall disables antivirus tools and modifies security utilities to ensure undetected encryption.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: cryptowall deletes Volume Shadow Copies and backup directories to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: cryptowall uses process discovery to identify critical services and isolate targets for disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1486 Data Encrypted for Impact Impact
What they do: cryptowall encrypts victim files using strong symmetric cryptography to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: cryptowall invokes system recovery inhibition commands to prevent automatic file restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
1G6tQeWrwp6TU1qunLjdNmLTPQu7PnsMYd |
bitcoin | $276 | 3 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Victims (4)
Search, filter and paginate the victim timeline for Cryptowall. Showing 1–4 of 4.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Kankakee County id183 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | The Arc of Winnebago, Boone and Ogle Counties id181 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Dickson County Sheriff’s Office id175 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Durham, N.H. police department id174 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||