Cryxos malware family
Cryxos is a malware family tracked by MalwareAnalyzer by Cyble across 12 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-09. Observed ATT&CK techniques include T1112, T1059.004, T1105.
Corpus statistics
- Publicly analyzed samples: 12
- First seen: 2026-07-28
- Last seen: 2026-08-09
- Verdicts: malicious 7, suspicious 5
- File types: script 5, html 4, unknown 3
ATT&CK techniques used by Cryxos
Extracted command-and-control infrastructure
- http://rediskina.com/f/gstats - 4 samples
- http://api.echoenabled.com/f/gstats - 1 sample
- http://cv01.twirpx.net/0364/0364133.jpg - 1 sample
- http://motormudejar.com/ - 1 sample
- http://ogp.me/ns/fb# - 1 sample
- http://virginestate.weebly.com/1/post/2016/12/shpargalki-po-metodike-prepodavaniya-matematike-v-nachaljnoj-shkole.html - 1 sample
- http://virginestate.weebly.com/blog/shpargalki-po-metodike-prepodavaniya-matematike-v-nachaljnoj-shkole&is_mobile=&r=3&is_light=1 - 1 sample
- https://indiazinhalindoya.com.br/vmc/ - 1 sample
- https://www.weebly.com/signup?utm_source=internal&utm_medium=footer - 1 sample
Recent Cryxos samples
- 8f15690542ab569af490780a95c128226923561db9da685228b2afd982eea49f - malicious (2026-08-09)
- 2da776c2d32acd5d0849a164d7bfe013a4a2fa3765cc1ac0c2be270f0d3316bf - suspicious (2026-08-08)
- 645f620b09f5e2b2ff22e54a8cf0ea83d6b523c9e9dc243f723e2adae1e5d191 - suspicious (2026-08-03)
- 9497146355d4566546a787b652c8f7aa9740f980795a9300fcff4c4a73e353e4 - malicious (2026-08-03)
- virussign.com_9ae49ead7877e73d1ed9856c4673f450.vir - malicious (2026-08-01)
- c8f5154d2662341069adbac8a2447b7e409300a7683ec93a9ee3312f16ec2b26.bin - malicious (2026-07-31)
- 04812630dcb086af236a69d05fbd85d4e6359c118048cacf2a1964ee330c2204.js - malicious (2026-07-30)
- 9fe0b14c1af0acf4cee1fa9c3c9a036db51002b683ff26d8c5c4e99be1084beb - malicious (2026-07-29)
- 240750c78b7938dcfcfa96ff246f13e8878d225301e1e4b852718ca13883fae4 - suspicious (2026-07-29)
- c953d99a62dd7bcf08737728e622ae3563a2543af5ca409a0c1988a13027dd67 - suspicious (2026-07-29)
- aca8d820afc61815a276f4810f5effaf71ad5dc8990b60323a1d1361654c63e3 - malicious (2026-07-29)
- 046c529ce1063a6a302925fa2cc4804fc16d1e8ce33ec883f99869f018461f71.js - suspicious (2026-07-28)
Frequently asked about Cryxos
- What is Cryxos?
- Cryxos is a malware family tracked by MalwareAnalyzer by Cyble across 12 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-09. Observed ATT&CK techniques include T1112, T1059.004, T1105.
- How many Cryxos samples have been analyzed?
- MalwareAnalyzer by Cyble holds 12 publicly analyzed samples attributed to Cryxos, first seen 2026-07-28 and most recently 2026-08-09. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Cryxos use?
- Across our Cryxos samples the most frequently observed techniques are T1112 (3), T1059.004 (1), T1105 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Cryxos use?
- Cryxos samples in this corpus are distributed as script (5), html (4), unknown (3).
- Does Cryxos use command-and-control infrastructure?
- Yes. 9 distinct command-and-control indicators have been extracted from Cryxos samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Cryxos malicious?
- 7 of 12 analyzed Cryxos samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends