---
title: "Getting to the Crux (Ransomware) of the Matter"
url: https://daily.dev/posts/getting-to-the-crux-ransomware-of-the-matter-5vqsre7gl
source_url: https://www.huntress.com/blog/crux-ransomware
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:20.910Z
updated: 2026-05-31T08:07:16.111Z
tags: ["ransomware"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting to the Crux (Ransomware) of the Matter

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 5 min read · 0 upvotes · 0 comments

## Summary

Huntress has identified a new ransomware variant called Crux, observed across three separate incidents in early July 2025. The threat actors claim affiliation with the BlackByte ransomware-as-a-service group. Encrypted files use the .crux extension and ransom notes reference BlackBCruxSupport@onionmail.org. Initial access in at least one incident was via RDP using valid credentials. The ransomware follows a distinctive process tree: unsigned binary → svchost.exe → cmd.exe → bcdedit.exe, the latter used to disable system recovery. Additional TTPs include remote Registry dumping, driver installation, lateral movement, and data exfiltration via Rclone. Indicators of compromise including file hashes, paths, and a driver file are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/crux-ransomware>

---

Tags: [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/getting-to-the-crux-ransomware-of-the-matter-5vqsre7gl)
