Crypto24 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known campaigns, and defensive recommendations. This report provides Mjolnir Security's analysis of the group's operations, extortion model, known targeting, and recommended defenses.
Overview
Crypto24 is a ransomware and/or data extortion operation tracked by Mjolnir Security. The group maintains a presence on the dark web where victim data is published to pressure payment. Operations typically involve double extortion: encrypting victim systems and threatening to leak stolen data.
Crypto24 is an active ransomware/extortion threat. Organizations should review their ransomware readiness posture and ensure backup, detection, and incident response capabilities are current.
Tactics & Techniques
Common MITRE ATT&CK techniques observed in ransomware operations like Crypto24:
| Technique | Description |
|---|---|
| T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |
| T1078 | Valid Accounts |
| T1059.001 | PowerShell Execution |
| T1567.002 | Exfiltration to Cloud Storage |
Detection & Defense
Recommended defenses against Crypto24 and similar ransomware groups:
- Offline backups: Maintain tested, immutable backups disconnected from production networks
- EDR/XDR: Deploy endpoint detection with behavioral ransomware protection and rollback
- Network segmentation: Limit lateral movement and isolate critical systems
- MFA everywhere: Enforce multi-factor authentication on all remote access and admin accounts
- Patch management: Prioritize patching of internet-facing appliances (VPN, Exchange, etc.)
- Incident response plan: Maintain and test a ransomware-specific IR playbook
How Mjolnir Security Can Help
Ransomware Defense & Response
Mjolnir Security provides ransomware readiness assessments, incident response, and threat intelligence to help organizations defend against extortion threats.
Contact us: mjolnirsecurity.com
Stay ahead of emerging threats. Get notified when we publish new intelligence reports.
Subscribe to Alerts