Crypto24 is a Windows ransomware operation that emerged in late 2023 and has targeted large enterprises in the United States, Europe, and Asia, including organizations in financial services, manufacturing, entertainment, and technology. It conducts double extortion, exfiltrating victim data before encrypting files and threatening public disclosure. Encrypted files receive a Crypto24-specific extension and victims receive a ransom note.
Crypto24 intrusions have included reconnaissance of hosts, disks, operating-system details, local accounts, and group memberships; manipulation and creation of privileged local accounts; remote execution and lateral movement through PsExec, WMI, Remote Desktop Protocol, and other administrative tooling; and installation of additional remote-access software. The operation maintains persistence through scheduled tasks and Windows services masquerading as legitimate service-hosted components. A custom keylogger captures keyboard activity and active-window titles, then uploads collected information and other stolen data through Google Drive APIs.
A prominent defense-evasion component is a customized RealBlindingEDR-like tool that identifies security-product drivers and disables associated kernel callbacks, impairing endpoint protection. Operators have also used Group Policy mechanisms and a legitimate endpoint-security uninstaller after obtaining administrative privileges to disable security controls. The ransomware employs VMProtect virtualization, API hashing, a CMSTPLUA COM UAC bypass, Volume Shadow Copy deletion, and post-encryption self-deletion and cleanup routines to hinder analysis, recovery, and forensic investigation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated double-extortion ransomware operation that establishes service-based persistence, bypasses UAC via the CMSTPLUA COM interface, encrypts files with a .crypto24 extension, deletes shadow copies, and threatens public exposure of stolen data. It uses VMProtect, API hashing, execution-context checks, and anti-forensic self-deletion and registry-cleanup routines.
Ransomware operation that compromises victim networks, exfiltrates data for extortion, and leaks stolen data on a dark web data leak site when ransom is not paid.
Ransomware family/operation that performs double extortion (data theft + encryption), appends the .crypto24 extension, drops a ransom note (Decryption.txt), uses service-based persistence (MSRuntime via svchost.exe), employs VMProtect and API hashing for evasion/anti-analysis, attempts to disable defenses and delete shadow copies, and terminates sync/cloud processes to maximize encryption impact.
Ransomware group using a combination of legitimate tools and custom malware to conduct stealthy attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.