Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks
Trend AI Research Blog Aug 2025

Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks

RansomwareDefense Evasion

Crypto24 is a ransomware group that stealthily blends legitimate tools with custom malware, using advanced evasion techniques to bypass security and EDR technologies. The group's toolkit includes living-off-the-land binaries mixed with custom-developed payloads, making detection through traditional signature-based methods extremely difficult. This research documents the full attack lifecycle, tool analysis, and provides behavioral detection strategies for identifying Crypto24 operations in enterprise environments.