CryptoLuck targets Windows OS and is distributed via the RIG exploit kit through malvertising. It infects systems through a legitimate code-signed GoogleUpdate.exe file and DLL hijacking. CryptoLuck has anti-detection features which allow it to check to see if it’s running within a virtual machine.

