logo

New Crypto24 Ransomware Attacks Bypass EDR

ID: d0e7cee5-e321-5f1a-b36f-e99301147bde

STIX ID: report--d0e7cee5-e321-5f1a-b36f-e99301147bde

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-08-15

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Trend Micro researchers warn of an active Crypto24 ransomware campaign that demonstrates advanced technical capabilities — including a customized RealBlindingEDR tool that neutralizes callbacks for nearly 30 security vendors, use of legitimate admin utilities (PSExec, AnyDesk, gpscript.exe, XBCUninstaller.exe) for post‑compromise actions, and likely use of vulnerable drivers (BYVOD) to evade EDRs — with big‑game hunting targeting large enterprises across financial services, manufacturing, entertainment, and tech in Asia, Europe, and the US.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.