Cryptolocker is back - What you should look for
Summary
This blueAPACHE post reports: Another batch of Cryptolocker emails are arriving in inboxes across Australia. Over the past few weeks we have seen five variants – ranging from a poor attempt at a credit card balance email from JP Morgan, to infringement notifications from AFP Australia. It concerns Managed Detection & Response. Published in 2015. Figures, product names and event details reflect that time; for current information see the linked service pages.
Key facts
| Label | Value |
|---|---|
| Publication year | 2015 |
| Services referenced | Managed Detection & Response |
| Topic | Cryptolocker is back - What you should look for |
Article
Another batch of Cryptolocker emails are arriving in inboxes across Australia. Over the past few weeks we have seen five variants – ranging from a poor attempt at a credit card balance email from JP Morgan, to infringement notifications from AFP Australia. Those behind the latter seem to think that the Australian Federal Police manage traffic violations. Fortunately, they are easy to identify as fake (hovering your mouse over the links shows the true destination) so they shouldn’t cause too many concerns – but they do serve as an opportunity to remind staff that hostage-ware remains prevalent and they need to be vigilant about the links and attachments they click. If you’re not familiar with this family of hostage-ware, we have written articles on Cryptolocker, and provided a deep dive into why they will be around for some time to come. The five we have seen are:
1. Refunds from the Australian Tax Office
This attempt does well to mask the sender’s email address by making it appear legitimate, but the address seen when hovering your mouse over the link points to a completely different site.

2. Faxes from the Australian Tax Office
This is likely from the same source as the refund statement above. It is only by hovering over the link address that the true destination is seen.

3. Australia Post Delivery notifications
Also replicating the model used in 1 and 2, the sender’s email address appears correct, but the link exposed exposed when you hover over the link shows that it is again redirecting you to a another site.

4. Traffic Infringement Notice from the Australian Federal Police
These are a little more obvious. Even if you believe that the AFP are now issuing traffic tickets, the sender’s actual email address (traffic-notice24@sdacourier.info) and the link should be enough to alert you something is not quite right.

5. JP Morgan Credit Card Balance
It’s unlikely you have a JP Morgan Credit Card, but even if you did – the sender’s email address and the link address exposed when hovering the link should be enough to stop you from clicking the link.

More information
For more information on Cryptolocker, click here. For more information on how to better secure your business, speak to the blueAPACHE account team.
Related
Frequently asked questions
How many Cryptolocker email variants does the post describe, and what do they impersonate?
The post describes five variants observed at the time: a fake Australian Tax Office refund email, a fake ATO fax notification, a fake Australia Post delivery notification, a fake Australian Federal Police traffic infringement notice, and a fake JP Morgan credit card balance email.
What sender address does the post give as an example of a suspicious link?
For the fake AFP traffic infringement email, the post gives the sender address traffic-notice24@sdacourier.info as an example of an address that should alert recipients something is wrong.
What single check does the post recommend to spot these fake emails?
The post recommends hovering the mouse over links (without clicking) to reveal the true destination address, which it says is enough to expose all five variants as fake.
What does the post say organisations should do about hostage-ware risk generally?
It says these emails serve as a reminder that hostage-ware remains prevalent and staff need to stay vigilant about links and attachments, and points to blueAPACHE's earlier Cryptolocker articles for more detail.
Is this post still current?
No. It describes specific 2015 phishing campaigns. For blueAPACHE's current threat detection services, see the Managed Detection & Response page linked below.
Source
https://www.blueapache.com/blog/cryptolocker-is-back-what-you-should-look-for-2/
Knowledge Base
What is the blueAPACHE blog post 'Cryptolocker is back – What you should look for' about?
The post discusses a new batch of Cryptolocker (ransomware/hostage-ware) emails arriving in inboxes across Australia, describing five variants seen over the past few weeks and reminding staff to be vigilant about links and attachments they click.
When was the 'Cryptolocker is back – What you should look for' article published?
The article was published on July 1, 2015, and takes about 2 minutes to read.
Who wrote the 'Cryptolocker is back' blog post?
The post was written by blueAPACHE.
What are the five Cryptolocker email variants identified in the blueAPACHE article?
The five variants identified are: 1) Refunds from the Australian Tax Office, 2) Faxes from the Australian Tax Office, 3) Australia Post Delivery notifications, 4) Traffic Infringement Notice from the Australian Federal Police, and 5) JP Morgan Credit Card Balance.
How can someone tell that the 'Refunds from the Australian Tax Office' email is fake, according to the article?
The email masks the sender's address to appear legitimate, but hovering the mouse over the link reveals it points to a completely different, illegitimate site.
What clue in the 'Traffic Infringement Notice from the Australian Federal Police' email reveals it as fake?
The sender's actual email address (traffic-notice24@sdacourier.info) and the destination link, visible when hovering over it, indicate the email is not legitimate, especially since the AFP does not issue traffic tickets.
What general advice does the article give for spotting these fake Cryptolocker emails?
The article advises hovering your mouse over links in emails to reveal their true destination, since this is how the fake sender addresses and malicious links can be identified across all five variants described.
Does the blueAPACHE article provide links to further Cryptolocker information?
Yes, the article links to two other blueAPACHE articles: one on 'Cryptolocker threats are increasing' and a 'deep dive' piece called 'Cryptolocker – a deeper look,' for readers wanting more background on this family of hostage-ware.
What does the article suggest businesses do to better secure themselves against threats like Cryptolocker?
The article suggests speaking to the blueAPACHE account team for more information on how to better secure your business.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c0fddcde676dc9f3234_cryptolocker08.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c13ddcde676dc9f32b6_Cryptolocker-is-back-1.png
Cryptolocker is back - example
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c13ddcde676dc9f32c0_Cryptolocker-is-back-2.png
Cryptolocker is back - example 2
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c13ddcde676dc9f32c6_Cryptolocker-is-back-3.png
Cryptolocker is back - example 3
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c13ddcde676dc9f32b3_Cryptolocker-is-back-4.png
Cryptolocker is back - example 4
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c13ddcde676dc9f32c3_Cryptolocker-is-back-5.png
Cryptolocker is back - example 5
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.