Ransomware Intelligence

crypto24

Ransomware group profile

37Victims
58Impact score

Description

Crypto24 is a ransomware group that emerged in July 2024, operating under a Ransomware-as-a-Service model with a focus on financial gain through data encryption and extortion. Known for its use of legitimate IT tools combined with custom malware, the group conducts stealthy, multi-stage attacks and primarily targets organizations during off-peak hours to evade detection.

Key insights

  • Utilizes phishing and exploited RDP services for initial access.
  • Employs proprietary ransomware that appends a '.crypto24' extension to encrypted files.
  • Implements a double extortion scheme, threatening to leak stolen data if ransom is not paid.
  • Uses legitimate administrative tools like PSExec and AnyDesk for lateral movement.
  • Targets various sectors including manufacturing, healthcare, and legal services.

Threat Level & Status Breakdown

For crypto24 · Based on incidents in selected period

2.7threat level
Aggressiveness5/ 10
Lethality0.3/ 10
Criticality3/ 10

Status Breakdown

Data Leaked5.4%2
Claimed13.5%5
First seenJun 2025
Last seenApr 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for crypto24 in the selected period

37Total attacks
9peak in Jul
3.4avg / month
↓ 1 vs first month
JunJulAugSepOctNovDecJanFebMarApr036912

Intelligence

IOCs, YARA/Sigma rules, and related families for crypto24

  1. ec5076aa5ac6ba904d33b8979c60dce1
  2. 3922461290fa663ee2853b2b5855afab0d39d799
  3. 3b0b4a11ad576588bae809ebb546b4d985ef9f37ed335ca5e2ba6b886d997bac
  4. eeafb2d4f6ed93ab417f190abdd9d3480e1b7b21
  5. 686bb5ee371733ab7908c2f3ea1ee76791080f3a4e61afe8b97c2a57fbc2efac
  6. 0eae3b3db725dbd017852e0d752184f5
  7. 7c5c87616c50cc04dd707ed4b620ba53
  8. 24f7b66c88ba085d77c5bd386c0a0ac3b78793c0e47819a0576b60a67adc7b73
  9. 8057d42ddb591dbc1a92e4dd23f931ab6892bcac
View full IOC feed9 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for crypto24

Other

T1486

T1486

T1490

T1490

T1021

T1021

T1562

T1562

T1078

T1078

T1547

T1547

T1059

T1059

T1046

T1046

T1021.001

T1021.001

T1037

T1037

T1080

T1080

T1071

T1071

Victims(37)

CompanyDomainCountryIndustryStatusDiscovered
Qatar Biomedical Research Institute (QBRI)hbku.edu.qaQA QatarEducation
Claimed
about 2 months ago
Katcon Globalkatcon.comMX MexicoManufacturing
Claimed
2 months ago
Industrias Guerra, S.A.iguerra.comES SpainManufacturing
Claimed
2 months ago
ActionPoweractionpower.krHR CroatiaEnergy & Utilities
Claimed
2 months ago
Estudio O'Farrellestudio-ofarrell.comAR ArgentinaProfessional Services
Claimed
2 months ago
Invaccs software technologies pvt ltdinvaccs.comIN IndiaTechnology
Unknown
3 months ago
Comprehensive Orthopaedics and Musculoskeletal Care, LLCcomprehensiveorthopaedics.comUS United StatesHealthcare
Unknown
3 months ago
Rowad Modern Engineeringrowad-rme.comEG EgyptOther
Unknown
3 months ago
Putnam Precision, Inc.putnamprecision.comUS United StatesManufacturing
Unknown
4 months ago
MRC Prion Unit and Institute of Prion Diseasesucl.ac.ukGB United KingdomHealthcare
Unknown
4 months ago
Yource Bulgaria & Greeceyourcebulgaria.ccBG BulgariaProfessional Services
Unknown
4 months ago
Unified Assessment Platform ExamRoom.AIexamroom.aiUS United StatesEducation
Unknown
5 months ago
SASP SNCC AUTOMATISME SOLUTIONS PROCESSsasp.frFR FranceTechnology
Unknown
6 months ago
Hollysys Asia Pacifichollysys.comSG SingaporeTechnology
Unknown
6 months ago
AsahiKASEI MICRODEVICESakm.comUS United StatesTechnology
Unknown
7 months ago
Bayu Buana Travelbayubuanatravel.comID IndonesiaHospitality
Unknown
7 months ago
Mei ***IT ItalyTechnology
Unknown
7 months ago
Meinhardt Groupmeinhardtgroup.comSG SingaporeOther
Unknown
7 months ago
Bayu Buana Travel Servicebayubuanatravel.comID IndonesiaHospitality
Unknown
7 months ago
U.S. Vanadium Holding Company LLCusvanadium.comUS United StatesManufacturing
Unknown
8 months ago

Page 1 of 2