Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1056.001 ↗inferred | Input Capture: Keylogging | Collection | Trend Micro: custom WinMainSvc.dll keylogger (runs only under svchost.exe) captures keystrokes incl. control keys and active window titles. |
| T1219 ↗inferred | Remote Access Tools | Command and Control | Trend Micro: AnyDesk and TightVNC installed for persistent interactive remote access. |
| T1036.004 ↗inferred | Masquerading: Masquerade Task or Service | Defense Evasion | Trend Micro / BleepingComputer: keylogger service masquerades as 'Microsoft Help Manager' and ransomware service as 'Microsoft Runtime Manager', both hosted under svchost.exe. |
| T1562.001 ↗inferred | Impair Defenses: Disable or Modify Tools | Defense Evasion | Trend Micro: customised RealBlindingEDR (AVB.exe/AVMon.exe) removes kernel callbacks for Trend Micro, Kaspersky, Sophos, SentinelOne, Bitdefender, McAfee, Fortinet, Broadcom, Cisco, Acronis etc. via driver-metadata matching; XBCUninstaller.exe run to remove Trend Vision One. |
| T1218 ↗inferred | System Binary Proxy Execution | Defense Evasion |
+17 more relationships — see the relationships browser.
| Trend Micro: gpscript.exe (LOLBin) used to launch VisionOne_removal_v2.bat from a network share, which invokes the legitimate XBCUninstaller.exe to uninstall the EDR agent. |
| T1082 ↗inferred | System Information Discovery | Discovery | Trend Micro: 1.bat recon script runs wmic partition get name,size,type and wmic COMPUTERSYSTEM get TotalPhysicalMemory,caption. |
| T1046 ↗inferred | Network Service Discovery | Discovery | Trend Micro: Angry IP Scanner (ipscan-3.9.1-setup.exe) dropped in %TEMP%\Low for network reconnaissance before lateral movement. |
| T1569.002 ↗inferred | System Services: Service Execution | Execution | Trend Micro: PsExec / psexec64.exe used for remote command execution across hosts. |
| T1567.002 ↗inferred | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Exfiltration | Trend Micro: keylog data and stolen files uploaded to Google Drive via a custom WinINet-based tool (Test.txt upload check first). |
| T1490 ↗inferred | Inhibit System Recovery | Impact | BleepingComputer / Trend Micro: volume shadow copies deleted prior to running the encryptor. |
| T1486 ↗inferred | Data Encrypted for Impact | Impact | Trend Micro: MSRuntime-hosted encryptor appends .crypto24, drops Decryption.txt, kills cloud-sync/remote-desktop processes and self-deletes artifacts; VMProtect-packed with API hashing. |
| T1021.001 ↗inferred | Remote Services: Remote Desktop Protocol | Lateral Movement | Trend Micro: fDenyTSConnections set to 0 via reg.exe, firewall rule 'Open Remote Desktop' on 3389 via netsh, and termsrv.dll patched (takeown/icacls + m.ps1) to allow multi-session RDP. |
| T1053.005 ↗inferred | Scheduled Task/Job: Scheduled Task | Persistence | Trend Micro: scheduled tasks created to run %ProgramData%\Update\update.vbs and vm.bat for persistence. |
| T1543.003 ↗inferred | Create or Modify System Process: Windows Service | Persistence | Trend Micro: sc create WinMainSvc (keylogger) and MSRuntime / 'Microsoft Runtime Manager' (ransomware loader) as svchost.exe -k shared services. |
| T1136.001 ↗inferred | Create Account: Local Account | Persistence | Trend Micro (Aug 2025): operators activate default admin accounts and create local users (john, service.lot9, 00025436, NetUser, IT.Guest) via net.exe, adding them to Administrators / Remote Desktop Users. |
| T1548.002 ↗inferred | Abuse Elevation Control Mechanism: Bypass User Account Control | Privilege Escalation | Trend Micro: UAC bypass via the auto-elevated CMSTPLUA COM interface ({3E5FC7F9-9A51-4367-9063-A120244FBEC7}) alongside runas.exe and psexec64.exe -u/-p. |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Crypto24's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Crypto24's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.