CrossLock
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
CrossLock is a ransomware group that has been identified by the alias CrossLock and is known to operate from Brazil. The group first appeared in public reporting in mid‑2023 when it claimed responsibility for an attack on a Brazilian digital certificate provider. No other aliases or alternative names have been associated with the actor in the available sources.
The actor’s observed targeting focuses on organizations that manage digital trust infrastructure, specifically a company that issues SSL certificates and related PKI services located in Brazil. The stated objectives of the activity are financial, as the group demanded a ransom and later threatened to sell the stolen certificates to other criminals for use in signing malware. There is no explicit mention of espionage, disruption, or ideological motives in the reported incident.
CrossLock’s tactics include the use of ransomware that employs the chacha20 stream cipher combined with elliptic curve cryptography (ECC) for encrypting victim files. The group encrypted the entire network of the target, including virtual machines, and exfiltrated sensitive data such as SSL certificates, server databases, and documents. After encryption, the actors posted a portion of the stolen data on a leak site and attempted to negotiate with the victim, while also advertising the sale of valid certificates through a Tox messaging handle. No details about initial access vectors or additional tooling were provided in the sources.
Publicly available information does not establish any clear affiliation with a state sponsor or a larger criminal consortium for CrossLock. The group’s representatives told reporters that they are not a new entity, but no further attribution or links to other threat clusters have been documented.
The most significant publicly reported operation involving CrossLock is the April 16 2023 attack on Valid Certificadora Digital, a Brazilian digital certificate issuer. In that incident the group encrypted the victim’s network, stole approximately 1.5 GB of data including certificates and databases, leaked part of the material, and threatened to sell the certificates to enable malware signing unless a ransom was paid. This case remains the primary example of the group’s activity in the open source record.
Incidents
Attributed incidents are available to members.
3 incidents