Alpha Crypt

Alpha Crypt targets all versions of the Windows OS and spreads via the Angler exploit kit. It creates a randomly named executable file in the %AppData% folder and then performs a scan for all available drives, including removable media, network shares, and DropBox mappings. Once all drives are located, it begins locking files using AES encryption and deletes Shadow Volume Copies to prevent data restoration.

