Crypto24 Ransomware Bypasses EDR Solutions in Targeted Attacks
Summary
Hide ▲
Show ▼
Crypto24 ransomware actors are using advanced evasion techniques and custom tools to disable endpoint detection and response (EDR) solutions, including Trend Micro's Vision One platform. These attacks target large enterprises across financial services, manufacturing, entertainment, and tech industries in Asia, Europe, and the US. The threat actors leverage legitimate tools and custom variants of RealBlindingEDR to neutralize security controls and maintain persistence. The attacks demonstrate significant technical expertise and strategic planning, posing a considerable risk to enterprise security. Organizations are advised to strengthen access controls, implement anti-tampering measures, and regularly audit privileged accounts to mitigate the threat.
Timeline
-
15.08.2025 21:49 📰 1 articles · ⏱ 1mo ago
Crypto24 Ransomware Bypasses EDR Solutions in Targeted Attacks
Crypto24 ransomware actors have been observed using advanced evasion techniques and custom tools to disable endpoint detection and response (EDR) solutions. These attacks target large enterprises across financial services, manufacturing, entertainment, and tech industries in Asia, Europe, and the US. The threat actors leverage legitimate tools and custom variants of RealBlindingEDR to neutralize security controls and maintain persistence. The attacks demonstrate significant technical expertise and strategic planning, posing a considerable risk to enterprise security. Organizations are advised to strengthen access controls, implement anti-tampering measures, and regularly audit privileged accounts to mitigate the threat.
Show sources
- New Crypto24 Ransomware Attacks Bypass EDR — www.darkreading.com — 15.08.2025 21:49
Information Snippets
-
Crypto24 ransomware was first spotted in 2024 and has recently escalated its attacks, targeting large enterprises.
First reported: 15.08.2025 21:49📰 1 source, 1 articleShow sources
- New Crypto24 Ransomware Attacks Bypass EDR — www.darkreading.com — 15.08.2025 21:49
-
Crypto24 actors use a combination of legitimate tools (PSExec, AnyDesk, Google Drive) and custom variants of RealBlindingEDR to bypass EDR solutions.
First reported: 15.08.2025 21:49📰 1 source, 1 articleShow sources
- New Crypto24 Ransomware Attacks Bypass EDR — www.darkreading.com — 15.08.2025 21:49
-
The attackers have demonstrated the ability to disable Trend Micro's Vision One platform using a legitimate uninstaller and a custom version of RealBlindingEDR.
First reported: 15.08.2025 21:49📰 1 source, 1 articleShow sources
- New Crypto24 Ransomware Attacks Bypass EDR — www.darkreading.com — 15.08.2025 21:49
-
Crypto24 targets industries including financial services, manufacturing, entertainment, and tech in Asia, Europe, and the US.
First reported: 15.08.2025 21:49📰 1 source, 1 articleShow sources
- New Crypto24 Ransomware Attacks Bypass EDR — www.darkreading.com — 15.08.2025 21:49
-
The custom RealBlindingEDR variant removes callbacks for security products from nearly 30 vendors, including Cisco, Kaspersky Lab, MalwareBytes, Sophos, and Trellix.
First reported: 15.08.2025 21:49📰 1 source, 1 articleShow sources
- New Crypto24 Ransomware Attacks Bypass EDR — www.darkreading.com — 15.08.2025 21:49
-
The attackers likely use a bring your own vulnerable driver (BYVOD) tactic to disable security tools.
First reported: 15.08.2025 21:49📰 1 source, 1 articleShow sources
- New Crypto24 Ransomware Attacks Bypass EDR — www.darkreading.com — 15.08.2025 21:49
Similar Happenings
UNC6040 and UNC6395 Target Salesforce Platforms in Data Theft Campaigns
The FBI has issued an alert about two cybercriminal groups, UNC6040 and UNC6395, targeting Salesforce platforms for data theft and extortion. UNC6395 exploited compromised OAuth tokens for the Salesloft Drift application, while UNC6040 used vishing campaigns and modified Salesforce tools to breach Salesforce instances. Both groups have been active since at least October 2024, impacting multiple organizations. UNC6040 has been linked to extortion activities, with Google attributing these to a separate cluster, UNC6240, which has claimed to be the ShinyHunters group. The ShinyHunters group, along with Scattered Spider and LAPSUS$, recently announced they are going dark, but experts warn that the threat persists. UNC6040 impersonated corporate IT support personnel to gain access to Salesforce environments and used modified versions of Salesforce's Data Loader to exfiltrate data. Salesforce re-enabled integrations with Salesloft technologies, except for the Drift app, which remains disabled.
Akira Ransomware Group Exploits SonicWall SSL VPN Flaws
The Akira ransomware group has been actively exploiting SonicWall SSL VPN flaws and misconfigurations to gain initial access to networks. This campaign has seen increased activity since late July 2025, targeting SonicWall devices to facilitate ransomware operations. The group leverages a combination of security vulnerabilities, including a year-old flaw (CVE-2024-40766) and misconfigured LDAP settings, to bypass access controls and infiltrate networks. Organizations are advised to rotate passwords, remove unused accounts, enable multi-factor authentication, and restrict access to the Virtual Office Portal to mitigate risks. The Australian Cyber Security Centre (ACSC) has acknowledged Akira's targeting of SonicWall SSL VPNs and issued alerts about the increased exploitation of CVE-2024-40766.
U.S. sanctions Southeast Asian cyber scam operations stealing billions from Americans
The U.S. Department of the Treasury has imposed sanctions on several large cyber scam networks in Southeast Asia, particularly in Burma and Cambodia. These operations, which stole over $10 billion from Americans in 2024, are known for using forced labor, human trafficking, and physical violence. The scams include 'romance baiting' and fake cryptocurrency investment schemes. The financial damage to Americans increased by 66% compared to the previous year. The sanctions target 19 entities and individuals linked to the Karen National Army (KNA) in Burma and various organized crime networks in Cambodia. These entities are involved in running scam centers, providing infrastructure, and facilitating money laundering. The sanctions block these entities from the U.S. financial system, freeze their U.S. assets, and limit their access to international financial services. The cybercriminal syndicates in Southeast Asia are estimated to net nearly $40 billion annually in illicit profits. In May 2025, OFAC targeted Funnull Technology Inc. and its administrator Liu Lizhi for their part in romance scams that caused more than $200 million in losses. In July 2025, Cambodian law enforcement raided several cyber-scam centers, arresting more than 1,000 people. The cybercriminal operations have led to the growth of entire cities along national borders, especially in conflict zones and special economic zones (SEZs).
Increased browser targeting by threat actors
Threat actors are increasingly targeting web browsers as a primary attack vector. This shift is driven by the browser's central role in accessing sensitive data and cloud applications, making it an attractive target for credential theft and session hijacking. High-profile incidents, such as the Snowflake breach, underscore the need for enhanced browser security measures. The browser's role in accessing sensitive data and cloud applications makes it a prime target for attackers. The Snowflake breach, which exploited stolen credentials, highlights the risks associated with browser-based attacks. Experts emphasize the need for stronger browser security to mitigate these threats. Browser-based attacks include phishing for credentials and sessions, malicious copy & paste (ClickFix), malicious OAuth integrations, malicious browser extensions, malicious file delivery, and exploiting stolen credentials and MFA gaps. These attacks exploit the browser's role in accessing business applications and data, making it crucial for security teams to focus on browser security.
Salty2FA Phishing Kit Demonstrates Enterprise-Level Sophistication
The Salty2FA phishing kit has evolved to incorporate enterprise-grade features, making it difficult to distinguish from legitimate software. The kit's advanced capabilities include subdomain rotation, abuse of legitimate platforms, dynamic corporate branding, MFA mimicry, and sophisticated defense evasion tactics. Ontinue researchers tracked a campaign using Salty2FA, observing its technical innovations and how it mimics legitimate enterprise systems. The campaign impersonated a known business using a trial account on Aha.io and deployed a OneDrive sharing page as the initial attack vector. The kit's infrastructure supports dynamic branding and advanced evasion techniques, making it challenging for security teams to detect and mitigate. The kit's advanced features include geo-blocking, ASN/IP filtering, and JavaScript-based anti-debugging, which hinder the efforts of security researchers and SOC teams. The Salty2FA phishing kit targets industries including finance, energy, healthcare, government, logistics, IT consulting, education, construction, telecom, chemicals, industrial manufacturing, real estate, and consulting. Salty2FA activity began gaining momentum in June 2025, with early traces possibly dating back to March–April 2025. Salty2FA campaigns have been active since late July 2025, generating dozens of fresh analysis sessions daily. The kit uses a multi-stage execution chain, including email lures, redirects to fake login pages, credential theft, and 2FA bypass techniques. Salty2FA employs Cloudflare checks to bypass automated filters and uses fake Microsoft-branded login pages to steal credentials. The kit intercepts push, SMS, and voice-based 2FA codes, leading to account takeovers. ANY.RUN sandbox analysis provides full-chain visibility of Salty2FA attacks, revealing behavioral patterns and reducing analyst workload. Defenders are advised to adopt advanced, layered protection and a behavioral-oriented approach to counter these evolving threats.