Netskope Threat Labs

TeslaCrypt

ATP Sandbox Adv. HeuristicsAV

TeslaCrypt is ransomware that was active from 2015 to 2016 and initially targeted gamers by encrypting game saves and related files. Its operators expanded to general users through spam campaigns and exploit kits, and its frequent variant updates frustrated early decryption attempts. The developers shut the operation down in 2016 and released decryption keys, which allowed researchers to build a universal decrypter, a rare positive ending for a major ransomware family.

First seen
February 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Ransomware.TeslaCrypt
Gen:Variant.Ransom.TeslaCrypt.117
Gen:Variant.Ransom.TeslaCrypt.118
Gen:Variant.Ransom.TeslaCrypt.238
Gen:Variant.Ransom.TeslaCrypt.24
Gen:Variant.Ransom.TeslaCrypt.89
Gen:Variant.Ransom.TeslaCrypt.98
Gen:Variant.TeslaCrypt.13
Gen:Variant.TeslaCrypt.16
Gen:Variant.TeslaCrypt.26