Back to Hub

Crypto24 Ransomware Bypasses EDR Defenses in Global Attacks

Imagen generada por IA para: Crypto24 Ransomware Evade Defensas EDR en Ataques Globales

A sophisticated new ransomware operation dubbed Crypto24 has emerged as a significant global threat, specifically targeting enterprise networks with tools designed to bypass modern endpoint security solutions. Cybersecurity researchers have observed the group employing advanced techniques to evade Endpoint Detection and Response (EDR) systems, making detection particularly challenging for security teams.

The Crypto24 operation stands out for its use of Bring Your Own Vulnerable Driver (BYOVD) techniques - a growing trend among advanced threat actors. This approach involves exploiting vulnerable but legitimate drivers to gain kernel-level access, allowing attackers to disable or circumvent security products before deploying ransomware payloads.

Technical analysis reveals that Crypto24 operators first gain initial access through compromised RDP credentials or phishing campaigns. Once inside a network, they perform extensive reconnaissance to identify high-value targets before moving laterally. The ransomware payload is typically deployed after attackers have disabled security solutions using their kernel-level access.

Industry Impact:
The ransomware has shown particular interest in multinational corporations across three key sectors:

  1. Financial services (banks, payment processors)
  2. Manufacturing (especially automotive and aerospace)
  3. Technology (SaaS providers and IT services)

Defensive Recommendations:
Security teams should consider implementing the following measures:

  • Monitor for suspicious driver loading events
  • Implement driver allowlisting policies
  • Enable kernel-mode hardware-enforced stack protection
  • Conduct regular audits of administrative credentials

The emergence of Crypto24 highlights the evolving sophistication of ransomware operations and underscores the need for defense-in-depth strategies that go beyond traditional EDR solutions.

Original sources

NewsSearcher

This article was generated by our NewsSearcher AI system, analyzing information from multiple reliable sources.

Crypto24 Ransomware Targets Global Firms with EDR-Evading Tools

WebProNews
View source

Ransomware Groups Deploy BYOVD for Kernel EDR Killers

WebProNews
View source

⚠️ Sources used as reference. CSRaid is not responsible for external site content.

This article was written with AI assistance and reviewed by our editorial team.

Comentarios 0

¡Únete a la conversación!

Sé el primero en compartir tu opinión sobre este artículo.