Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services, healthcare, manufacturing, and technology across Asia, Europe, and North America, with notable victims including CMC Group, Vietnam's second-largest ICT conglomerate. Known victims: 46 1 ransom note(s) on file
Objectives
Executive Summary
Crypto24 is a mid-sophistication ransomware-as-a-service (RaaS) group emerged in mid-2024, specializing in double-extortion campaigns targeting large enterprises across financial services, healthcare, manufacturing, and technology sectors globally. Operating with high organizational efficiency, the group has demonstrated significant operational persistence since their first detection in December 2023, with a notable victim list including major corporates like CMC Group and Vietnam's second-largest ICT company. Their primary modus operandi involves encrypting victims' data and demanding substantial ransoms for decryption keys, often coupled with threats to leak sensitive information unless paid.
Goals & Targeting
Crypto24's strategic objectives are centered around maximizing financial gain through high-impact ransomware campaigns. They target sectors with significant data and revenue exposure, including financial services, healthcare, manufacturing, and technology. Their global reach across Asia, Europe, and North America suggests a focus on densely populated industrial regions to maximize attack surface and victim pool. The choice of victims reflects a balance between organizational size and criticality of operations to ensure successful ransom payments while avoiding excessive attention from law enforcement.
Enhanced Description
Crypto24 represents a sophisticated criminal ransomware group that operates as an affiliate program in the cybercrime ecosystem. The group primarily uses double-extortion tactics, where they encrypt victim files and additionally threaten to publish stolen data if their demands are not met. This business model has allowed them to target a diverse range of industries globally, including financial services, healthcare providers, manufacturing companies, and technology firms across Asia, Europe, and North America. Known for their operational persistence since mid-2024, Crypto24 has demonstrated both technical skill and strategic planning in their campaigns. The group's emergence on the RAMP forum signifies a shift towards more sophisticated criminal operations, leveraging aaaS models to expand their attack capabilities. Their targeting of major corporate entities suggests a focus on high-value targets with deep financial pockets, aligning with their primary motivation of organizational-gain through ransom payments.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Crypto24's campaigns exhibit a pattern of targeting large, geographically dispersed enterprises. Their operational tempo is steady with periodic spikes in activity following major incidents. Notable campaigns include attacks on CMC Group and other high-profile organizations. The group leverages both custom malware and existing ransomware frameworks, often supported by robust command-and-control infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Crypto24's operational model, IOCs, and targeting patterns. Limited visibility into the group's internal structure and exact TTPs exists beyond their observable campaign data and known aliases.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
8
Campaigns
2
IOCs
0
Observed Data
0
Tactics