ZeroHour

crypto24

ransomware group · aka Crypto24, CZ (leak-site branding; used by some trackers) · Unknown; 2025 vendor research reported tooling and procedural overlaps suggesting possible ties to former Black Basta operators (unconfirmed) · active since Late 2024 / early 2025 (initial public tracking; exact date unknown)

Victims · 7d
0flat
Victims · 30d
1active targets
Victims · 90d
1
All-time (tracked)
51since 2025-04-08
Last post
08-31 13:38UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Crypto24 is a ransomware and data-extortion group first publicly tracked in late 2024/early 2025, associated with double-extortion attacks in which stolen data is published on its leak site. Some vendor research published in 2025 reported tooling and procedural overlaps suggesting possible ties to former Black Basta operators, though attribution remains unconfirmed. The group targets large enterprises and institutions across multiple regions, with leak-site victims spanning education and research, healthcare, manufacturing, legal services, technology, and construction. This dashboard has tracked its leak site since 2026-08-31, recording 1 listed victim and a last post on that date, reflecting an intermittent claiming pattern rather than high-volume activity. The group's listing of Qatar Biomedical Research Institute (QBRI) drew attention in Qatar regional threat coverage for 2025-26.

Tactics & tooling
  • Double extortion: encrypts victim systems and publishes or threatens to publish stolen data on a leak site
  • Selective big-game targeting of large enterprises and institutions, with named leak-site victims across the Americas, Europe, the Middle East, and Asia
  • Reported tooling and procedural overlaps with former Black Basta operators in 2025 vendor analyses (unconfirmed)
  • Intermittent leak-site cadence with multi-week to multi-month gaps between victim posts (observed in this dashboard's tracking)
  • Initial access techniques and affiliate model: not consistently documented in public reporting (unknown)
  • No specific exploited vulnerabilities (CVEs) widely attributed to the group in public reporting as of latest available research
Targeted sectors
Education and researchHealthcareManufacturingProfessional services (legal)Technology and softwareEngineering and constructionBusiness process outsourcing (BPO)Energy and power electronics
Notable public victims

Qatar Biomedical Research Institute (QBRI), MRC Prion Unit and Institute of Prion Diseases (UK medical research institute), Katcon Global, Estudio O'Farrell, ActionPower, Rowad Modern Engineering, Yource (Bulgaria and Greece operations), Putnam Precision, Inc., Comprehensive Orthopaedics and Musculoskeletal Care, LLC

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Taxplan · Apr 8, 2025taxplann.ca 856.4GB Canada

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .