Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Crypto24 is a financially motivated ransomware operation that emerged in 2024 and focuses on large, high-value enterprises rather than opportunistic mass targeting. It is notable for stealth: operators blend legitimate IT and remote-administration tools with custom malware, including a keylogger and a customized RealBlindingEDR-based tool used to disable endpoint protection before deployment. Attacks follow a coordinated multi-stage playbook of initial access, credential harvesting, lateral movement, data exfiltration to cloud storage, and encryption. Public reporting is relatively recent and limited, so parts of this profile carry moderate confidence.
Crypto24 came to public attention in 2024. Technical samples were reportedly first detected around September 2024, aggregator tracking (ransomware.live) estimates an earliest associated intrusion as early as December 2023, and the group is said to have surfaced on the Russian-language RAMP cybercrime forum in mid-2024. These dates come from different sources and are not fully reconciled, so the precise emergence timeline should be treated as approximate (medium-to-low confidence). The name 'Crypto24' has also appeared on older, unrelated malware; this profile concerns the enterprise-focused ransomware operation only.
The defining characteristic of Crypto24, documented in detail by Trend Micro in August 2025, is operational stealth and a deliberate 'living-off-the-land' tradecraft. Rather than relying on noisy custom tooling, operators lean on legitimate administrative utilities — PSExec for lateral movement, AnyDesk and TightVNC for persistent remote access, and Windows-native binaries (LOLBins) such as gpscript.exe. Persistence and reconnaissance are established quietly, with attacks frequently timed to off-peak hours to reduce the chance of detection.
The group pairs these legitimate tools with bespoke malware. A custom keylogger is deployed as a Windows service (WinMainSvc.dll) to harvest credentials and keystrokes, with collected data staged and uploaded to Google Drive — the same channel used for stealthy data exfiltration ahead of encryption. Most distinctively, Crypto24 uses a customized variant of the open-source RealBlindingEDR tool to strip kernel callbacks belonging to a predefined list of nearly 30 security vendors (reported to include Trend Micro, Cisco, Kaspersky, Malwarebytes, Sophos, and Trellix), and abuses gpscript.exe to run a legitimate Trend Vision One uninstaller — turning off protection before the ransomware payload executes. Operators have also been observed patching termsrv.dll to enable multiple concurrent RDP sessions. The end objective is double extortion: sensitive data is stolen first, systems are then encrypted, and victims are pressured via a Tor-based leak site.
Reported victimology concentrates on large corporations and enterprise-scale organizations in Asia, Europe, and the United States, spanning financial services, manufacturing, technology, professional services, entertainment, and healthcare. Trend Micro's primary analysis did not attribute a country of origin and did not characterize the group as RaaS versus a closed crew; aggregator sources describe it as a double-extortion, possibly RaaS-style operation, but this is lower-confidence secondary reporting. As of the most recent public reporting the operation remained active.
+17 more relationships — see the relationships browser.
MENA relevance: Direct MENA reporting is thin — Trend Micro's regional breakdown names only Asia, Europe, and the USA and does not mention the Middle East; the RaqibCTI Egypt and UAE tags trace to the group's own data-leak-site postings as catalogued by ransomware.live (Egypt: Rowad Modern Engineering and International Business Service; UAE: TransCore ITS, LLC; with adjacent regional claims for Qatar and Azerbaijan), meaning they are self-proclaimed, unverified leak-site claims rather than independently confirmed targeting, so the MENA tags should be retained but explicitly flagged as low-confidence / unverified.