# Overview Thirteen years before this piece—during the fall of 2013—reports appeared of a new ransomware campaign called Cryptolocker. The malware encrypted victims' files and demanded payment in bitcoin or other virtual currencies. Although ransomware existed earlier, Cryptolocker brought wide attention to the threat because of its rapid spread and sizable financial impact.
# How it spread Early distribution relied on social engineering. Spam messages carried ZIP file attachments that purported to contain customer complaints. The message text used plausible workplace scenarios—problematic checks or shipment alerts—to prompt recipients to open attachments or click links. Some emails impersonated shipping services such as UPS or FedEx.
Clicking the link or opening the attachment often delivered a Trojan—identified in many cases as Gameover Zeus. That Trojan attached infected machines to a botnet, which then installed Cryptolocker. The combination of convincing social-engineering lures and botnet delivery allowed fast, broad propagation across organizations and individual users.
# Scale and cost By mid-December 2013, security experts estimated up to 250,000 computers were infected worldwide, with roughly half of those located in the United States. The U.S. Department of Justice later reported that ransom payments associated with Cryptolocker totaled an estimated $27 million. The payments were made in bitcoin and similar virtual currencies, which complicated tracing and recovery.
# Disruption and attribution
# Why this episode matters Cryptolocker exposed how effective simple social-engineering messages could be when paired with malware delivered by a botnet. It also highlighted the financial incentives driving ransomware: victims were willing to pay to regain access to critical files, creating a profitable criminal model. The takedown showed that coordinated international action can disrupt infrastructure, but attribution and apprehension of key actors can remain unresolved.
# Short timeline
# Practical takeaway Cryptolocker combined simple, believable social-engineering lures with botnet-delivered malware to achieve rapid spread and significant ransom payments. The episode illustrates two enduring defenses: skepticism toward unexpected attachments or links, and infrastructure-based responses—coordinated disruption of command-and-control servers—by law enforcement and security partners.
Photo credit listed in original reporting: Gorodenkoff / Shutterstock
Author of the original piece: Kate Johanns