Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors crypto24

Description

Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services, healthcare, manufacturing, and technology across Asia, Europe, and North America, with notable victims including CMC Group, Vietnam's second-largest ICT conglomerate. Known victims: 46 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Crypto24 is a mid-sophistication ransomware-as-a-service (RaaS) group emerged in mid-2024, specializing in double-extortion campaigns targeting large enterprises across financial services, healthcare, manufacturing, and technology sectors globally. Operating with high organizational efficiency, the group has demonstrated significant operational persistence since their first detection in December 2023, with a notable victim list including major corporates like CMC Group and Vietnam's second-largest ICT company. Their primary modus operandi involves encrypting victims' data and demanding substantial ransoms for decryption keys, often coupled with threats to leak sensitive information unless paid.

Goals & Targeting

Crypto24's strategic objectives are centered around maximizing financial gain through high-impact ransomware campaigns. They target sectors with significant data and revenue exposure, including financial services, healthcare, manufacturing, and technology. Their global reach across Asia, Europe, and North America suggests a focus on densely populated industrial regions to maximize attack surface and victim pool. The choice of victims reflects a balance between organizational size and criticality of operations to ensure successful ransom payments while avoiding excessive attention from law enforcement.

Enhanced Description

Crypto24 represents a sophisticated criminal ransomware group that operates as an affiliate program in the cybercrime ecosystem. The group primarily uses double-extortion tactics, where they encrypt victim files and additionally threaten to publish stolen data if their demands are not met. This business model has allowed them to target a diverse range of industries globally, including financial services, healthcare providers, manufacturing companies, and technology firms across Asia, Europe, and North America. Known for their operational persistence since mid-2024, Crypto24 has demonstrated both technical skill and strategic planning in their campaigns. The group's emergence on the RAMP forum signifies a shift towards more sophisticated criminal operations, leveraging aaaS models to expand their attack capabilities. Their targeting of major corporate entities suggests a focus on high-value targets with deep financial pockets, aligning with their primary motivation of organizational-gain through ransom payments.

Key Capabilities

  • Double-extortion ransomware deployment
  • Sophisticated phishing campaigns
  • Exploitation of software vulnerabilities
  • Encryption of sensitive data for monetary extortion

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access

ATT&CK Techniques

T1059.003
T1055
T1078

Software / Tooling

Ransomware payload delivery framework

Campaigns & Victims

Crypto24's campaigns exhibit a pattern of targeting large, geographically dispersed enterprises. Their operational tempo is steady with periodic spikes in activity following major incidents. Notable campaigns include attacks on CMC Group and other high-profile organizations. The group leverages both custom malware and existing ransomware frameworks, often supported by robust command-and-control infrastructure.

IOC Patterns

  • Spear-phishing emails mimicking trusted entities
  • Distribution of malicious Office documents with embedded scripts (e.g., VBA)
  • C2 communication via hardcoded domains or IPs (e.g., 45.63.9.192:5050)
  • Encrypted files with specific extension patterns

Recommended Actions

  • Implement multi-factor authentication for critical systems
  • Monitor for suspicious network traffic originating from known Crypto24 IOCs
  • Conduct regular backups of critical data and isolate backup servers
  • Enhance employee training on identifying phishing attempts
  • Deploy endpoint detection and response (EDR) solutions

Suggested Tags

ransomware
double extortion
cybercrime-as-a-service

Confidence Assessment

High confidence in Crypto24's operational model, IOCs, and targeting patterns. Limited visibility into the group's internal structure and exact TTPs exists beyond their observable campaign data and known aliases.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1 Email Address 1

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

8

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
ransomware
double extortion
cybercrime-as-a-service

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 13, 2023
Last Seen
Apr 17, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.