CryptoRoger targets Windows OS and the method of distribution is currently unknown. Once executed, this variant encrypts targeted files using AES-256 and then stores the MD5 hash of the original, non-encrypted file, placing it in the %AppData%\files.txt file. Files encrypted by CryptoRoger are appended with the extension .crptrgr.

