Threat Actor Profile
Low
Cybercriminal
Description
According to OALabs, this ransomware has the following features: * Files are encrypted with AES CBC using a generated 256 bit key and IV.* The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
Confidence Score
Tags
ransomware
ransomware.live
First Seen
Unknown
Last Updated
Unknown
Active Status
ActiveCreated
April 29, 2026
Indicators of Compromise
Loading IOCs…
IOC KQL for Sentinel
STIX Data
{'added_date': None,
'client': '2003264@sit.singaporetech.edu.sg',
'description': ' According to OALabs, this ransomware has the following '
'features: * Files are encrypted with AES CBC using a '
'generated 256 bit key and IV.* The generated AES keys are '
'encrypted using a hard coded RSA key and appended to the '
'encrypted files.',
'firstseen': '2023-04-19T20:00:01.214643+00:00',
'group': 'cryptnet',
'has_negotiations': False,
'has_ransomnote': True,
'lastseen': '2023-04-19T20:00:01.214643+00:00',
'locations': [{'available': False,
'fqdn': 'blog6zw62uijolee7e6aqqnqaszs3ckr5iphzdzsazgrpvtqtjwqryid.onion',
'slug': 'http://blog6zw62uijolee7e6aqqnqaszs3ckr5iphzdzsazgrpvtqtjwqryid.onion/',
'title': 'CryptNet NEWS',
'type': 'DLS'},
{'available': False,
'fqdn': 'cryptr3fmuv4di5uiczofjuypopr63x2gltlsvhur2ump4ebru2xd3yd.onion',
'slug': 'http://cryptr3fmuv4di5uiczofjuypopr63x2gltlsvhur2ump4ebru2xd3yd.onion/login',
'title': 'CryptNet RECOVERY',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 1,
'tiaras_metadata': {'has_negotiations': False,
'has_ransomnote': True,
'locations': [{'available': False,
'fqdn': 'blog6zw62uijolee7e6aqqnqaszs3ckr5iphzdzsazgrpvtqtjwqryid.onion',
'slug': 'http://blog6zw62uijolee7e6aqqnqaszs3ckr5iphzdzsazgrpvtqtjwqryid.onion/',
'title': 'CryptNet NEWS',
'type': 'DLS'},
{'available': False,
'fqdn': 'cryptr3fmuv4di5uiczofjuypopr63x2gltlsvhur2ump4ebru2xd3yd.onion',
'slug': 'http://cryptr3fmuv4di5uiczofjuypopr63x2gltlsvhur2ump4ebru2xd3yd.onion/login',
'title': 'CryptNet RECOVERY',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 1,
'ransomware_live_group': 'cryptnet',
'tools': {},
'url': 'https://www.ransomware.live/group/cryptnet',
'victims': 2,
'vulnerabilities': []},
'tiaras_source': 'ransomware.live',
'tools': {},
'ttps': [],
'url': 'https://www.ransomware.live/group/cryptnet',
'victims': 2,
'vulnerabilities': []}