Ip
1 total45.63.9.192:5050
Crypto24 is a Windows ransomware operation that emerged in late 2023 and has targeted large enterprises in the United States, Europe, and Asia, including organizations in financial services, manufacturing, entertainment, and technology.
Profile source: Mallory opens in a new tabCrypto24
Crypto24 is a Windows ransomware operation that emerged in late 2023 and has targeted large enterprises in the United States, Europe, and Asia, including organizations in financial services, manufacturing, entertainment, and technology. It conducts double extortion, exfiltrating victim data before encrypting files and threatening public disclosure. Encrypted files receive a Crypto24-specific extension and victims receive a ransom note.
Crypto24 intrusions have included reconnaissance of hosts, disks, operating-system details, local accounts, and group memberships; manipulation and creation of privileged local accounts; remote execution and lateral movement through PsExec, WMI, Remote Desktop Protocol, and other administrative tooling; and installation of additional remote-access software. The operation maintains persistence through scheduled tasks and Windows services masquerading as legitimate service-hosted components. A custom keylogger captures keyboard activity and active-window titles, then uploads collected information and other stolen data through Google Drive APIs.
A prominent defense-evasion component is a customized RealBlindingEDR-like tool that identifies security-product drivers and disables associated kernel callbacks, impairing endpoint protection. Operators have also used Group Policy mechanisms and a legitimate endpoint-security uninstaller after obtaining administrative privileges to disable security controls. The ransomware employs VMProtect virtualization, API hashing, a CMSTPLUA COM UAC bypass, Volume Shadow Copy deletion, and post-encryption self-deletion and cleanup routines to hinder analysis, recovery, and forensic investigation.
45.63.9.192:5050crypto24support@pm.meMITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.