May 12, 2023, 3:30 p.m. | Santiago Vicente

Security Boulevard securityboulevard.com

Key Points


CryptNet is a new ransomware-as-a-service that has been advertised in underground forums since at least April 2023

The CryptNet threat group claims to perform double extortion attacks by combining data exfiltration with file encryption

The ransomware code is written in the .NET programming language

CryptNet uses 256-bit AES in CBC mode and 2048-bit RSA to encrypt files

The CryptNet ransomware codebase is closely related to Chaos ransomware


Zscaler ThreatLabz has been tracking a new ransomware group known as …

aes analysis april as-a-service attacks claims code data data exfiltration double extortion encryption exfiltration extortion file file encryption forums key key points language mode programming programming language ransomware service technical technical analysis threat threat group underground

Digital Security Infrastructure Manager

@ Wizz Air | Budapest, HU, H-1103

Sr. Solution Consultant

@ Highspot | Sydney

Cyber Security Analyst III

@ Love's Travel Stops | Oklahoma City, OK, US, 73120

Lead Security Engineer

@ JPMorgan Chase & Co. | Tampa, FL, United States

GTI Manager of Cybersecurity Operations

@ Grant Thornton | Tulsa, OK, United States

GCP Incident Response Engineer

@ Publicis Groupe | Dallas, Texas, United States