<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p><strong>CryptXXX</strong> is a crypto-ransomware that debuted in April, 2016, and is <a href="https://www.proofpoint.com/us/threat-insight/post/cryptxxx-new-ransomware-actors-behind-reveton-dropping-angler">said</a> to be&nbsp;by&nbsp;the makers of <strong>Reveton</strong>, a very well-known police ransomware that terrorized victims at the beginning of the decade. Recently, <strong>CryptXXX</strong> has been&nbsp;spreading rapidly&nbsp;through&nbsp;phishing emails with&nbsp;malicious attachments, which lead to an attack chain using&nbsp;<strong>Neutrino</strong> and, previously, <strong>Angler</strong> exploit kits to ultimately download the ransomware.</p> <!--more--><p><strong>CryptXXX</strong> shows prominence through its active development and rapid evolution. Versions 1 and 2 of this young ransomware were decrypted fairly&nbsp;quickly by&nbsp;Kaspersky, yet a third&nbsp;version which is currently <a href="https://www.proofpoint.com/us/threat-insight/post/cryptxxx-ransomware-learns-samba-other-new-tricks-with-version3100">non-decryptable</a>&nbsp;surfaced not long afterwards. The strong&nbsp;capabilities&nbsp;that this ransomware has adapted over time&nbsp;include locking the screen of the victims' machines after encryption and network share encryption, and the use of a downloaded DLL to <a href="https://www.proofpoint.com/us/threat-insight/post/cryptxxx-ransomware-learns-samba-other-new-tricks-with-version3100">steal</a> victims' data, which can be used by the criminals for further monetization or&nbsp;for targeted attacks.</p> <p>ThreatSTOP customers are protected from <strong>CryptXXX</strong>, as well as <strong>Angler</strong>&nbsp;and <strong>Neutrino</strong> exploit kits.</p></span>