Ransomware Group intelligence
Crypto24
ActiveTrack Crypto24 with 48 published victims and 1 known leak locations in a single intelligence view.
Overview
Crypto24 is tracked by Breach House as a ransomware group with 48 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 3h ago | j5o5y2feotmhvr7cbcp2j2ewayv5mn5zenl3joqwx67gtfchhezjznad.onion |
Top Activity Sectors (11)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Crypto24, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: crypto24 executes malicious commands via PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: crypto24 modifies Windows Registry Run Keys to maintain persistence across reboots after initial compromise.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: crypto24 disables antivirus tools by terminating security processes and modifying system policies to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: crypto24 forces Safe Mode Boot to bypass user account control and execute privileged ransomware components.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1070.004 File Deletion Stealth
What they do: crypto24 deletes Volume Shadow Copies and backup directories via command-line utilities to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: crypto24 performs remote system discovery to map victim infrastructure before deploying ransomware payloads.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: crypto24 scans network shares using native tools to identify victim file directories for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: crypto24 leverages SMB/Windows Admin Shares for lateral movement across networked servers in targeted environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: crypto24 encrypts victim files using custom symmetric encryption routines to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: crypto24 invokes system recovery inhibition commands to lock down restore mechanisms and prolong impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
Decryption.txt
*** We are Crypto24 Group *** *** Your files have been encrypted and stolen *** We have exfiltrated over 200 GB of your most sensitive business data from your internal network. - Prepress files for every product. - Personnel, HR, and customer records. - Databases, including PCFactory. - Finance, accounting, and QA logs ⏳ [ WHAT TO DO NEXT ] You have 3 days to contact us. After that, the price will increase. If we receive no response in 7 days, your data will be published on our TOR leak site: http://j5o5y2feotmhvr7cbcp2j2ewayv5mn5zenl3joqwx67gtfchhezjznad.onion (Access via TOR browser: https://www.torproject.org/download/) 💬 [ CONTACT INSTRUCTIONS ] Use the Session messenger: - Download: https://getsession.org/download - Contact Session ID: 05e034eb421832ae9209e9c17441c93ee4509f2e6dae2b23595763e0a19fdcee52 - Device ID: [snip] Please include your **Company Name** and **Device ID** in your first message. 🔒 [ TEST DECRYPTION OFFER ] To prove we can restore your files, we offer free decryption of: - 1 document file (under 1MB) - 1 image file (under 5MB) 🚫 [ DO NOT TRUST UNVERIFIED “RECOVERY EXPERTS” ] You may try to recover your data on your own or with a security firm. However, we strongly advise against involving third parties who are not officially trusted by you. Do not share your device ID with untrusted third parties. The device ID is an identifier that proves that you are a victim. Some so-called “recovery experts” will ask for your Device ID. They will then contact us pretending to be you, get a test decryption from us, and act like they did it themselves. They’ll show you the decrypted file, make you believe they can recover everything, and take your money. In the end, they disappear. You lose time, money, and trust. Your Device ID means nothing to them technically — but it helps them fool you. We are the only ones with the keys. Don’t waste your time or budget chasing illusions. ⚠️ [ DO NOT ATTEMPT DIY DECRYPTION ] You are free to try recovery attempts with your own tools or with trusted providers. But we strongly recommend that you **create backups first**. If you damage or overwrite any encrypted files, not even we can restore them. No tool, no expert, and no government can break our encryption without the key. ✅ [ WHY CHOOSE US ] We are professionals. If anyone else or any organization claims to be able to decrypt it, it is a scam. The strength of the encryption makes it impossible for anyone other than us to decrypt it. The sooner you contact us, the lower the cost — and the faster your business can get back on track. **We are the only ones who can actually solve this.** Act quickly. Every hour counts. Contact us now to begin the recovery. Time is running out.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (48)
Search, filter and paginate the victim timeline for Crypto24. Showing 1–48 of 48.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Me*** id32319 View details | Singapore | — | — | |
|
Me*** is a ransomware victim entity operating within the Singapore sector, documented within a threat-intelligence index. Its profile outlines the organization’s sector context and geographic location as Singapore, reflecting operational scope relevant to cyber threat monitoring. The entity is formally listed as a ransomware victim associated with the threat actor crypto24. This entry serves threat analysts by cataloging affected entities alongside their linked actors and regional context without disclosing unverified incident details. The description maintains neutrality and avoids speculative claims regarding breach specifics, data impacts, or resolution outcomes. |
|||||
| Ransomware | Qatar Biomedical Research Institute (QBRI) id28259 View details | Qatar | Education | — | |
|
[AI generated] Qatar Biomedical Research Institute (QBRI) is a research institute based in Qatar, operating under Hamad Bin Khalifa University. It focuses on biomedical research in areas such as genomics, diabetes, cancer, and neurological disorders. QBRI aims to advance precision medicine and translational research to address health challenges prevalent in Qatar and the broader region, contributing to the country's science and innovation goals. |
|||||
| Ransomware | Katcon Global id27824 View details | Mexico | Manufacturing / Engineering | — | |
|
[AI generated] "Katcon Global" is a prominent automotive supplier, specialized in the field of developing, designing, and manufacturing advanced vehicle exhaust systems. Established in 1993 in Mexico, the company has now expanded worldwide at multiple locations, including Europe, Asia, Australia, and America. Besides exhaust systems, Katcon also provides solutions in energy recovery and sustainability sectors. |
|||||
| Ransomware | Industrias Guerra, S.A. id27823 View details | Spain | Transportation / Travel / Logistics | — | |
|
[AI generated] Industrias Guerra, S.A. is a prominent Spanish company known for the manufacturing of marine cranes, forestry machinery, and special equipment. Its products serve sectors like construction, recycling, mining, and shipping. The company emphasizes high-quality, sustainable production and has been operating successfully since its establishment in 1947. |
|||||
| Ransomware | ActionPower id27610 View details | Korea, Republic of | IT | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Estudio O'Farrell id27540 View details | Argentina | Finance / Legal / Insurance | — | |
|
[AI generated] Estudio O'Farrell is a prestigious law firm based in Buenos Aires, Argentina. Known for its comprehensive legal services, the firm specializes in areas such as corporate law, tax law, banking and finance, and labor law among others. Having a history of over 130 years, Estudio O'Farrell has represented multiple high-profile clients and is renowned for its professional and innovative legal solutions. |
|||||
| Ransomware | Invaccs software technologies pvt ltd id27221 View details | India | IT | — | |
|
[AI generated] Invaccs Software Technologies Pvt Ltd is a technology company, based in India, that specializes in providing information technology and consulting services. They offer solutions in cutting-edge technologies like Blockchain, artificial intelligence, IoT, and software development. Their services are designed to assist businesses with digital transformation, efficiency improvement, and competitive advantage creation. |
|||||
| Ransomware | Comprehensive Orthopaedics and Musculoskeletal Care, LLC id27210 View details | United States | Communication / Marketing | — | |
|
HIPAA personal information for over 100,000 people... |
|||||
| Ransomware | Rowad Modern Engineering id27090 View details | Egypt | Manufacturing / Engineering | — | |
|
[AI generated] Rowad Modern Engineering is an Egypt-based construction firm specializing in the implementation and delivery of various construction projects. The company offers services ranging from civil engineering and construction management to project costing and risk management. It has a prominent role in constructing infrastructure, roads, commercial, and residential buildings. |
|||||
| Ransomware | Putnam Precision, Inc. id26375 View details | United States | Communication / Marketing | — | |
|
[AI generated] Putnam Precision, Inc. is a prominent manufacturing firm based in the USA, specializing in high-grade custom, precision components. The company primarily services the medical, semi-conductor and aerospace industries. Putnam uses state-of-the-art technology to ensure accuracy & quality in their products, with services including CNC machining, milling, turning, and assembly operations. |
|||||
| Ransomware | MRC Prion Unit and Institute of Prion Diseases id25740 View details | United Kingdom | Communication / Marketing | — | |
|
According to our guidelines, full data will be released once the timer expires. |
|||||
| Ransomware | Yource Bulgaria & Greece id25661 View details | Bulgaria | Communication / Marketing | — | |
|
Yource Bulgaria & Greece is a customer experience and contact center services provider supporting major international clients, handling large volumes of sensitive personal and business data across its operations in Bulgaria and Greece. We possess internal data belonging to Yource Bulgaria & Greece, including HR, customer, financial, and project-related information, as well as customer datasets associated with client engagements involving organizations such as Eneco Belgium, bofrost, essent.be, Media Compentence, Sodexo, and Spotzer. |
|||||
| Ransomware | Unified Assessment Platform ExamRoom.AI id25027 View details | United States | Other | — | |
|
*** |
|||||
| Ransomware | SASP SNCC AUTOMATISME SOLUTIONS PROCESS id24854 View details | France | Communication / Marketing | — | |
|
*** |
|||||
| Ransomware | Hollysys Asia Pacific id24322 View details | Singapore | Manufacturing / Engineering | — | |
|
[AI generated] Hollysys Asia Pacific is part of Hollysys Automation Technologies Ltd, a leading provider of industrial and rail transportation automation solutions. Its core businesses include industrial automation, rail transportation, and mechanical and electrical solutions. The company utilizes advanced technologies in industrial automation and control, digital rail signaling, and mechanical and electrical solutions to address modern industrial operations and infrastructure requirements. |
|||||
| Ransomware | Bayu Buana Travel Service id23908 View details | Indonesia | Transportation / Travel / Logistics | — | |
|
We have successfully extracted over 500GB of documents from your internal network, including internal company documents, customer and project information, and other data stored within your internal systems. |
|||||
| Ransomware | AsahiKASEI MICRODEVICES id23813 View details | United States | Other | — | |
|
... |
|||||
| Ransomware | Meinhardt Group id23359 View details | Singapore | Services | — | |
|
... |
|||||
| Ransomware | Bayu Buana Travel id23358 View details | Indonesia | Transportation / Travel / Logistics | — | |
|
... |
|||||
| Ransomware | Mei *** id23322 View details | Singapore | Other | — | |
|
Mei *** is a Singapore-based organization in the broad “Other” sector, which typically covers companies and institutions outside standard industry categories. As a named entity in threat-intelligence indexing, it is presented as an organization operating in Singapore rather than as a consumer brand or public agency. Public reporting in this listing context does not provide further verified detail about its offerings or business model. In ransomware monitoring, Mei *** was listed as a ransomware victim associated with crypto24. |
|||||
| Ransomware | U.S. Vanadium Holding Company LLC id23254 View details | United States | Retail / E-commerce | — | |
|
We have successfully extracted over 300GB of documents from your internal network, including internal company documents, customer and project information, and other data stored within your internal systems. |
|||||
| Ransomware | Banco Hipotecario del Uruguay id22742 View details | Uruguay | Finance / Legal / Insurance | — | |
|
We have exfiltrated over 700GB of most sensitive highly sensitive customer PII, financial/accounting records, legal/contracts, property/title documents, credit and risk files, market/trading operations data, and IT/security configuration information. |
|||||
| Ransomware | Generali Group id22472 View details | Italy | Services | — | |
|
*** |
|||||
| Ransomware | Palmgold Management Sdn Bhd id21817 View details | Malaysia | Finance / Legal / Insurance | — | |
|
We have exfiltrated over 500GB of most sensitive and business-critical data from palmgold's internal network. This includes data from both the Casino Division and the Credit Division, where the Casino Division holds the full operational database of over 60,000 members including PII, jackpot and play history, betting patterns, machine configurations, Power BI dashboards used for internal analytics, confidential finance, HR, and IT documents, complete scanner share contents from all branches (kmscan, toshibascan, fujiscan), as well as operational logic such as promotion formulas, game-specific revenue models, slot machine volatility settings, player-tier betting analytics, risk thresholds, fraud alert triggers, and blacklist criteria, while the Credit Division (pgcredit.com.my) contains all customer KYC information along with detailed banking and cash transaction records. |
|||||
| Ransomware | CMS Legal Services EEIG id21769 View details | Germany | Finance / Legal / Insurance | — | |
|
We are in possession of highly confidential data belonging to CMS, one of the largest international law firms, including government and national infrastructure project files, sensitive contracts with multinational corporations, tax authority system access records, internal financial and legal documents, as well as payroll and personnel information. The complete dataset and its full file list will be publicly released in its entirety. |
|||||
| Ransomware | Karndean International, LLC id21752 View details | United States | Finance / Legal / Insurance | — | |
|
We have exfiltrated over 600GB of your most sensitive corporate data, including financial, technical, operational, and personal information covering customers, employees, and strategic business plans. |
|||||
| Ransomware | Kar *** id21700 View details | Other | — | ||
|
... |
|||||
| Ransomware | SOUBEIRAN CHOBET S.R.L. id21315 View details | Argentina | Communication / Marketing | — | |
|
We have exfiltrated over 300GB of most sensitive and business-critical data from internal servers including full DBs including Microsoft Dynamics GP database, financials, accounting records, HR files, inventory logs, production processes, customer contracts, and complaint records, complete data analytics and marketing materials.And also have R&D and QC datasets, such as HPLC/FASE MOVIL outputs, experimental protocols, specialized pharmaceutical formulations, master batch records detailing proprietary production know-how, ANMAT/FDA CTDs, product recall logs, GMP audit results, deviation reports, and regulatory correspondence. |
|||||
| Ransomware | TransCore ITS, LLC id21247 View details | United Arab Emirates | Communication / Marketing | — | |
|
We’ve successfully breached the internal network of TransCore’s Dubai office.Over 200 GB of internal data has been exfiltrated, including in-development source code, full file sets from active and archived client projects, internal financial records, and a massive trove of unprotected customer data — all stored without proper safeguards.The stolen data contains clear violations of multiple NDAs, exposing confidential third-party materials and client information. |
|||||
| Ransomware | Sou *** id21218 View details | Other | — | ||
|
... |
|||||
| Ransomware | Artemis Healthcare, Inc id21192 View details | United States | Healthcare / Pharma | — | |
|
It contains sensitive personal data, including medical records, official documents, and imaging files of millions of patients, as well as various databases. |
|||||
| Ransomware | A-Qroup Sığorta Şirkəti id21191 View details | Azerbaijan | Healthcare / Pharma | — | |
|
The entire InsureAZ database has been leaked — including real insurance documents and all related materials such as medical, auto, and internal corporate records. |
|||||
| Ransomware | Tan Chong Motor Holdings Berhad id21190 View details | Malaysia | Finance / Legal / Insurance | — | |
|
We have exfiltrated over 300GB of sensitive data, including Customer databases (all dbs of tanchong - NAV, BRASSTAX, VTS, CRM, E-INVOICE,...),Legal and HR documents, Financial and employee records, Contractual documents with partners and customers. |
|||||
| Ransomware | Warisan TC Holdings Berhad id21189 View details | Malaysia | Finance / Legal / Insurance | — | |
|
We have exfiltrated over 300GB of sensitive data, including Customer databases (all dbs of wtc - TOURPLAN, CRM, E-INVOICE,...),Legal and HR documents, Financial and employee records, Contractual documents with partners and customers. |
|||||
| Ransomware | Larimart S.P.A id21188 View details | Italy | Communication / Marketing | — | |
|
We have secured 2TB of confidential data : NATO-linked armor specifications and ballistic protection designs,EUC/EUS certificates and UAMA export control documents,VTLM test data and confidential field performance results from Santa Severa,Strategic planning documents, internal pricing, MoD, invoices and tactical customer lists,Archives of confidential consortium contracts and weapon system development records. |
|||||
| Ransomware | Tra *** id21187 View details | Other | — | ||
|
... |
|||||
| Ransomware | Tien Tuan Pharmaceutical Machinery Co. Ltd id20458 View details | Viet Nam | Healthcare / Pharma | — | |
|
[AI generated] Tien Tuan Pharmaceutical Machinery Co. Ltd is a leading provider of integrated software solutions for the pharmaceutical industry. The Vietnam-based company specializes in offering digital solutions to optimize the pharmaceutical manufacturing and distribution process. Their products include solutions for pharmaceutical lifecycle management, manufacturing execution systems, and plant intelligence. Their clients are major global pharmaceutical and biotechnology companies. |
|||||
| Ransomware | FORTÉ id20451 View details | United States | Communication / Marketing | — | |
|
[AI generated] FORTÉ is a fitness-focused technology company that provides a subscription-based streaming platform. It offers live and on-demand access to boutique fitness classes led by top fitness studios and professionals. The platform is designed for multiple devices, allowing users to participate in the fitness classes from anywhere. Workouts range across a variety of styles, including yoga, cardiovascular exercises, strength training, and cycling among others. |
|||||
| Ransomware | Choice AG id20329 View details | Germany | Services | — | |
|
[AI generated] "Choice AG" is a Switzerland-based company that specializes in providing solutions for investment and risk management. It offers software as well as asset management services that cater towards institutional and private investors alike. Their solutions are geared to help clients manage risk while optimizing investment returns. Services range from portfolio management to risk analysis, covering various types of assets from bonds to real estate. |
|||||
| Ransomware | Elite Advanced Laser Corporation ( Elaser ) id20288 View details | Taiwan, Province of China | Communication / Marketing | — | |
|
[AI generated] Elite Advanced Laser Corporation, or Elaser, is a company that specializes in the manufacturing of semiconductor and printed circuit boards. They provide the exceedingly high technology of laser drilling machines, primarily used for producing microvia holes in several applications. Headquartered in Taoyuan City, Taiwan, the company strives for the high efficiency of laser production and developing innovations in the laser industry. |
|||||
| Ransomware | N8XT id19309 View details | Singapore | Communication / Marketing | — | |
|
3 TB data including Customer information, DB data, Technical documents, Projects data and Company-related documents etc ... in Servers and Nas. |
|||||
| Ransomware | CMC Corperation id19104 View details | Viet Nam | NGOs / Associations | — | |
|
2 TB data including Token Data, Database Data, Website Data, ... from MariaDB, MongoDB and RARS-DB etc ... in DataCenter. |
|||||
| Ransomware | ModulusGroup,Ludi-SFM id19083 View details | Monaco | Communication / Marketing | — | |
|
casino customer info, db, ERP data, casino system projects source code and so on. |
|||||
| Ransomware | Taxplan id19052 View details | Canada | Communication / Marketing | — | |
|
Tax-related documents and data, database and programs |
|||||
| Ransomware | Mochtar Karuwin Komar: Indonesian law firm - MKK id19051 View details | Indonesia | Finance / Legal / Insurance | — | |
|
Legal advice, case-related documents, financial information, contracts, billing |
|||||
| Ransomware | technoforte software pvt ltd id19050 View details | India | IT | — | |
|
All source codes of technoforte's main project - Palms(including mobile version) |
|||||
| Ransomware | International Busines Service id19049 View details | Egypt | Services | — | |
|
Identity cards including front and back of about 3,000 people (image, pdf), HR reports, Pay documents |
|||||
| Ransomware | Iris Neofinanciera id19048 View details | Colombia | Other | — | |
|
All files of google drives, google chatting data ,workmanager documents(for last 5years) ,sql dbs and personal information of clients and staffs. |
|||||