Skip to content

Crypto24

Crypto24 is a Windows ransomware operation that emerged in late 2023 and has targeted large enterprises in the United States, Europe, and Asia, including organizations in financial services, manufacturing, entertainment, and technology.

Profile source: Mallory opens in a new tab

Crypto24

Family profile

Crypto24 is a Windows ransomware operation that emerged in late 2023 and has targeted large enterprises in the United States, Europe, and Asia, including organizations in financial services, manufacturing, entertainment, and technology. It conducts double extortion, exfiltrating victim data before encrypting files and threatening public disclosure. Encrypted files receive a Crypto24-specific extension and victims receive a ransom note.

Crypto24 intrusions have included reconnaissance of hosts, disks, operating-system details, local accounts, and group memberships; manipulation and creation of privileged local accounts; remote execution and lateral movement through PsExec, WMI, Remote Desktop Protocol, and other administrative tooling; and installation of additional remote-access software. The operation maintains persistence through scheduled tasks and Windows services masquerading as legitimate service-hosted components. A custom keylogger captures keyboard activity and active-window titles, then uploads collected information and other stolen data through Google Drive APIs.

A prominent defense-evasion component is a customized RealBlindingEDR-like tool that identifies security-product drivers and disables associated kernel callbacks, impairing endpoint protection. Operators have also used Group Policy mechanisms and a legitimate endpoint-security uninstaller after obtaining administrative privileges to disable security controls. The ransomware employs VMProtect virtualization, API hashing, a CMSTPLUA COM UAC bypass, Volume Shadow Copy deletion, and post-encryption self-deletion and cleanup routines to hinder analysis, recovery, and forensic investigation.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

2
Indicators
1
YARA rules
1
Ransom notes
1
Leak sites
1 available

Published indicators

Ip

1 total
  • 45.63.9.192:5050

Email

1 total
  • crypto24support@pm.me

Recent claims

MITRE ATT&CK

Crypto24 in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.