{"id":6198,"date":"2025-08-16T10:04:27","date_gmt":"2025-08-16T10:04:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/16\/ransomware-actors-blending-legitimate-tools-with-custom-malware-to-evade-detection\/"},"modified":"2025-08-16T10:04:27","modified_gmt":"2025-08-16T10:04:27","slug":"ransomware-actors-blending-legitimate-tools-with-custom-malware-to-evade-detection","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/16\/ransomware-actors-blending-legitimate-tools-with-custom-malware-to-evade-detection\/","title":{"rendered":"Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection"},"content":{"rendered":"<p>    Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The cybersecurity landscape faces a new sophisticated threat as the Crypto24 ransomware group demonstrates an alarming evolution in attack methodology, seamlessly blending legitimate administrative tools with custom-developed malware to execute precision strikes against high-value targets.<\/p>\n<p>This emerging ransomware operation has successfully compromised organizations across Asia, Europe, and the United States, with a particular focus on financial services, manufacturing, entertainment, and technology sectors.<\/p>\n<p>Unlike conventional ransomware <a href=\"https:\/\/cybersecuritynews.com\/incorporating-cybersec-credentials-into-marketing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a> that rely heavily on encryption-focused attacks, Crypto24 operators exhibit exceptional operational maturity by strategically timing their attacks during off-peak hours to minimize detection risks while maximizing impact potential.<\/p>\n<p>The group\u2019s sophisticated arsenal includes legitimate tools such as PSExec for lateral movement, AnyDesk for persistent remote access, and keyloggers for credential harvesting, all integrated with Google Drive for stealthy data exfiltration capabilities.<\/p>\n<p>The threat actors demonstrate advanced technical expertise through their deployment of a customized version of RealBlindingEDR, an open-source tool designed to disable security solutions.<\/p>\n<p>Trend Micro analysts <a href=\"https:\/\/www.trendmicro.com\/en_no\/research\/25\/h\/crypto24-ransomware-stealth-attacks.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this variant as particularly dangerous due to its ability to neutralize modern defensive mechanisms, likely exploiting unknown vulnerable drivers to achieve kernel-level access and disable endpoint detection systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiD0oLNY7pAb4pxNs5_zL5b2nCsIWTuyT9n5nE-xZmlmqAgnQXpdxTuIar1UYfDJ05l4Xbe2TLcVANIC2FWfb0EJA4OwXjCSt1gtfqcFZs9XLv3YHj2mSq6ODjV8TASGBrgbUTo_3X_x9BOpPuNr3tkh6i8eYyvJkD1P7dByRzgWhbTrBu-1MiyKQadPTcW\/s16000\/The%2520Crypto24%2520ransomware%2520attack%2520chain%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">The Crypto24 ransomware attack chain (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p>What sets Crypto24 apart from other <a href=\"https:\/\/cybersecuritynews.com\/everest-ransomware-gang-leak-site-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a> operations is their methodical approach to understanding enterprise security stacks.<\/p>\n<p>The group has systematically studied defensive architectures and developed purpose-built tools to exploit identified weaknesses, representing a dangerous shift from opportunistic attacks to targeted, intelligence-driven operations that demonstrate patience and strategic planning uncommon in commodity ransomware.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-evasion-through-living-off-the-land-tactics\"><strong>Advanced Evasion Through Living Off The Land Tactics<\/strong><\/h2>\n<p>The most concerning aspect of Crypto24\u2019s methodology lies in their masterful exploitation of legitimate Windows utilities to achieve malicious objectives while maintaining operational stealth.<\/p>\n<p>The attackers leverage gpscript.exe, a legitimate Group Policy utility, to remotely execute security software uninstallers from network shares, effectively removing endpoint protection before lateral movement phases.<\/p>\n<p>The group\u2019s persistence mechanisms reveal sophisticated understanding of Windows architecture.<\/p>\n<p>They create multiple administrative accounts with generic names to avoid detection during routine security audits, using standard net.exe commands to establish privileged access.<\/p>\n<p>Their reconnaissance capabilities are equally advanced, employing batch files like 1.bat to gather comprehensive system intelligence through Windows Management Instrumentation Commands (WMIC).<\/p>\n<pre class=\"wp-block-code\"><code>wmic partition get name,size,type\nwmic COMPUTERSYSTEM get TotalPhysicalMemory,caption\nnet user\nnet localgroup<\/code><\/pre>\n<p>Perhaps most troubling is their deployment of WinMainSvc.dll as a <a href=\"https:\/\/cybersecuritynews.com\/how-to-detect-a-keylogger-on-your-computer-find-remove-keylogger-from-pc\/\" target=\"_blank\" rel=\"noreferrer noopener\">keylogger<\/a> service, configured to capture sensitive credentials while masquerading as legitimate system processes.<\/p>\n<p>The malware includes sophisticated evasion checks, ensuring execution only through svchost.exe to prevent sandbox analysis.<\/p>\n<p>This keylogger establishes persistent surveillance capabilities that outlast the initial infection, creating ongoing exposure risks for compromised organizations.<\/p>\n<p>The Crypto24 campaign represents a critical inflection point in ransomware evolution, where threat actors have moved beyond simple encryption schemes to develop comprehensive attack platforms that study, adapt to, and systematically defeat modern <a href=\"https:\/\/cybersecuritynews.com\/strengthening-digital-defenses-the-vital-role-of-cybersecurity-in-database-automation\/\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity defenses<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ransomware-actors-blending-legitimate-tools\/\">Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ransomware-actors-blending-legitimate-tools\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection The cybersecurity landscape faces a new sophisticated threat as the Crypto24 ransomware group demonstrates an alarming evolution in attack methodology, seamlessly blending legitimate administrative tools with custom-developed malware to execute precision strikes against high-value targets. This emerging ransomware operation has successfully compromised organizations across [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6198","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6198"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6198"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6198\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}