Ransomware needs a way in. Stolen credentials are the cheapest one.
crypto24 Ransomware Group
Ransomware group profile
Description
Crypto24 is a ransomware group that emerged in July 2024, operating under a Ransomware-as-a-Service model with a focus on financial gain through data encryption and extortion. Known for its use of legitimate IT tools combined with custom malware, the group conducts stealthy, multi-stage attacks and primarily targets organizations during off-peak hours to evade detection.
Key insights
- •Utilizes phishing and exploited RDP services for initial access.
- •Employs proprietary ransomware that appends a '.crypto24' extension to encrypted files.
- •Implements a double extortion scheme, threatening to leak stolen data if ransom is not paid.
- •Uses legitimate administrative tools like PSExec and AnyDesk for lateral movement.
- •Targets various sectors including manufacturing, healthcare, and legal services.
Threat Level & Status Breakdown
For crypto24 · Based on incidents in selected period
Recent activity
Monthly attack count for crypto24 in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for crypto24
- 10c3317566f52eaeb45294a544c8038cf132240a9d12aef95c0658d6a49f4d91
- 4aaf5558277d742b180e3208e4340cc98dd0b94baf5c940c5ef0b0c2d9eea707
- 79e349ed7488a90438fd4b72da5cfd8d844509aa48973a9aa1a9852d801dc08b
- e573f4c395b55664e5e49f401ce0bbf49ea6a540
- a60c6a07d3ba6c2d9bf68def208566533398fe8f
- 9a9f52554c1a9938725b7dabd0f27002b0f8e874
- eeafb2d4f6ed93ab417f190abdd9d3480e1b7b21
- 686bb5ee371733ab7908c2f3ea1ee76791080f3a4e61afe8b97c2a57fbc2efac
- ec5076aa5ac6ba904d33b8979c60dce1
- 8057d42ddb591dbc1a92e4dd23f931ab6892bcac
- 3b0b4a11ad576588bae809ebb546b4d985ef9f37ed335ca5e2ba6b886d997bac
- 0e36b1837e5a2cbd14fac2c3b709a5470b7b488bd15898d30840ec60448e83e0
- 71a528241603b93ad7165da3219e934b00043dd6
- f353a8387e1c1a526f1b02bd3d6558d6
- 47ba2db66791b92e6b5a12f35717bbe6286777794b7964efb6a509e51a4e74f1
- 093902737a7850c6c715c153cd13e34c86d60992
- c7a116e710a63eb0833e66562a30e8a0
- d2294aa892494220bd08e6cbbd16e3b744d03074a56dd897adc3614111cdc53d
- 5d1f44a2b992b42253750ecaed908c61014b735a
- 0eae3b3db725dbd017852e0d752184f5
- 24f7b66c88ba085d77c5bd386c0a0ac3b78793c0e47819a0576b60a67adc7b73
- 3922461290fa663ee2853b2b5855afab0d39d799
- ba4685594714e3ffde4f52a82cc07c6f94324215
- c4da41d0f40152c405ba399a9879d92b05ac1f61
- dd389b5f3bb7e946cc272bf01d412d661635f10b
- 74bc31f649a73821a98bef6e868533b6214f22a4
- b23d0939b17b654f2218268a896928e884a28e60
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for crypto24
T1486
T1486
T1490
T1490
T1021
T1021
T1562
T1562
T1078
T1078
T1547
T1547
T1059
T1059
T1046
T1046
T1021.001
T1021.001
T1037
T1037
T1080
T1080
T1071
T1071
Victims(19)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Hamad Bin Khalifa University (HBKU) | Qatar | Claimed | 5 months ago | |
| Katcon | Mexico | Claimed | 6 months ago | |
| Industrias Guerra | Spain | Claimed | 6 months ago | |
| ActionPower | Croatia | Claimed | 6 months ago | |
| O’Farrell | Argentina | Claimed | 6 months ago | |
| Invaccs | India | Claimed | 6 months ago | |
| Comprehensive Orthopaedics | United States | Claimed | 6 months ago | |
| Rowad Modern Engineering | Egypt | Claimed | 7 months ago | |
| Putnam Precision | United States | Claimed | 7 months ago | |
| University College London | United Kingdom | Claimed | 8 months ago | |
| Yource Bulgaria & Greece | Bulgaria | Claimed | 8 months ago | |
| ExamRoom.AI | United States | Claimed | 9 months ago | |
| SASP | France | Claimed | 9 months ago | |
| Hollysys Asia Pacific | Singapore | Claimed | 10 months ago | |
| AsahiKASEI MICRODEVICES | United States | Claimed | 10 months ago | |
| Bayu Buana Travel Services | Indonesia | Claimed | 11 months ago | |
| Meinhardt Group | Singapore | Claimed | 11 months ago | |
| U.S. Vanadium Holding Company LLC | United States | Claimed | 11 months ago | |
| Banco Hipotecario del Uruguay | Uruguay | Claimed | 12 months ago |
Affected countries(36)
Countries where this group has been reported to target or leak victims.