Crypto24

Compare
Parsing: enabled Known RaaS

View crypto

Description

aka Public Data Storage
Crypto24 emerged in early 2025 as a fast-growing double-extortion ransomware-as-a-service (RaaS) group. It targets organizations across industries such as financial services, healthcare, logistics, and technology, with notable victims in Malaysia, Colombia, Egypt, and India. The group executes rapid infiltration—often leveraging stolen credentials—encrypts files (appending the .crypto24 extension), and exfiltrates significant volumes of data (e.g., 2 TB from Vietnam’s CMC Group). Affiliate-oriented operations are indicated by their presence on RAMP forums, suggesting professional recruitment and offering free decryption for small file samples to entice victims.

External Analysis4
External Analysis
https://exchange.xforce.ibmcloud.com/threats/guid%3Afa7cb7e2ed554da0b7413eca362ed8f8
https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/crypto24
https://www.sangfor.com/blog/cybersecurity/vietnam-cmc-group-ransomware-attack-anatomy-asian-cyber-shock
https://www.cyfirma.com/research/tracking-ransomware-april-2025
Ransom notes1
Mail2
Mail
crypto24support@pm.me
noreply@crypto24lab.com
Session1
Session
05627a685204cef278f7c6d90cb8cb0e213bc58e858e9602faffd5c22f1024af79
Urls2
Url
Status
Screen
Uptime 30d
Health
http://j5o5y2feotmhvr7cbcp2j2ewayv5mn5zenl3joqwx67gtfchhezjznad.onion/ Up Screen
62%
http://j5o5y2feotmhvr7cbcp2j2ewayv5mn5zenl3joqwx67gtfchhezjznad.onion:5050/data Down Screen
Activity (interactive) 36
Activity charts
Posts36
Date Title Description Screen
Bayu Buana Travel Service
AsahiKASEI MICRODEVICES
Meinhardt Group
Bayu Buana Travel
Mei ***
U.S. Vanadium Holding Company LLC
Banco Hipotecario del Uruguay
Generali Group
Palmgold Management Sdn Bhd
CMS Legal Services EEIG
Karndean International, LLC
Kar ***
SOUBEIRAN CHOBET S.R.L.
TransCore ITS, LLC
Sou ***
Tra ***
Larimart S.P.A
Lar ***
Warisan TC Holdings Berhad We have exfiltrated over 300GB of sensitive data, including Customer databases (all dbs of wtc - TOURPLAN, CRM, E-INVOICE,...),Legal and HR documents, Financial and employee records, Contractual documents with partners and customers. Screen
Tan Chong Motor Holdings Berhad Data Size: 300GB We have exfiltrated over 300GB of sensitive data, including Customer databases (all dbs of tanchong - NAV, BRASSTAX, VTS, CRM, E-INVOICE,...),Legal and HR documents, Financial and employee records, Contractual documents with partners and customers. Screen
A-Qroup Sığorta Şirkəti Data Size: 730GB The entire InsureAZ database has been leaked — including real insurance documents and all related materials such as medical, auto, and internal corporate records. Screen
Artemis Healthcare, Inc 1TB It contains sensitive personal data, including medical records, official documents, and imaging files of millions of patients, as well as various databases. Screen
Sagence AI Data Size: 2.4TB This leak contains the full TSMC 5nm and 7nm Process Design Kits, UMC 40ULP PDK and FDK, along with confidential AI-related project data from internal R&D, including simulation models, layout files, hardware accelerator designs, and proprietary training architectures, all sourced directly from foundry servers. Screen
Tien Tuan Pharmaceutical Machinery Co. Ltd
FORTÉ
Choice AG
Elite Advanced Laser Corporation ( Elaser )
Elaser
N8XT
CMC Corperation 2 TB data including Token Data, Database Data, Website Data, ... from MariaDB, MongoDB and RARS-DB etc ... in DataCenter.
ModulusGroup,Ludi-SFM casino customer info, db, ERP data, casino system projects source code and so on.
Iris Neofinanciera iris.com.co 1TB Colombia
International Busines Service ibsns.com 2GB Egypt
technoforte software pvt ltd Technoforte.co.in 30GB India
Mochtar Karuwin Komar: Indonesian law firm - MKK mkklaw.net 700GB Indonesia
Taxplan taxplann.ca 856.4GB Canada
Note