Attribution
Unattributed financially motivated ransomware group. No public reporting ties Crypto24 to a specific nation-state or named prior crew, and no MITRE ATT&CK group ID has been assigned. It is a distinct operation from earlier unrelated malware that reused the generic 'Crypto24' string.
First seen
2024 (samples publicly detected around September 2024; ransomware.live estimates an earliest associated intrusion in December 2023, and the group is reported to have surfaced on the RAMP cybercrime forum in mid-2024 — exact emergence date is uncertain)
Last active
2025 (Trend Micro described ongoing campaigns as of its August 2025 analysis; leak-site activity continued through 2025)
Motivation
Financial gain via double extortion (data theft plus encryption, with victims pressured through a Tor-based data-leak site).
Attribution confidence
medium
Sectors
Manufacturing, technology, professional services
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Egypt, UAE (Manufacturing, technology, professional services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.