Ransomware Intelligence

krybit

Ransomware group profile

56Victims
73Impact score

Description

KryBit is a financially motivated ransomware group that emerged in March 2026, offering a Ransomware-as-a-Service model where affiliates retain a significant share of ransom payments. They employ a double-extortion strategy by encrypting files and exfiltrating sensitive data, with notable public conflicts with rival groups contributing to their visibility in the cybercriminal landscape.

Key insights

  • Utilizes a double-extortion model, encrypting files and stealing data.
  • Targets multiple operating systems, including Windows, Linux, and ESXi.
  • Ransom demands range between $40,000 to $100,000.
  • Employs complex evasion techniques, including shadow copy deletion and process injection.
  • Communicates with victims through Tor-based channels for negotiations.
  • Engages in inter-group conflicts that result in operational revelations.
  • Initial access often gained through phishing and exploited services.

Threat Level & Status Breakdown

For krybit · Based on incidents in selected period

3.9threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality1.5/ 10

Status Breakdown

Claimed100.0%56
First seenApr 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for krybit in the selected period

56Total attacks
24peak in Apr
18.7avg / month
↓ 7 vs first month
AprMayJun06121824

Intelligence

IOCs, YARA/Sigma rules, and related families for krybit

  1. oaptxiyisljt2kv3we2we34kuudmqda7f2geffoylzpeo7ourhtz4dad.onion
  2. zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion
  3. krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion
View full IOC feed3 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for krybit

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1562

T1562

T1059

T1059

T1021

T1021

T1547

T1547

T1021.001

T1021.001

T1105

T1105

T1037

T1037

T1071

T1071

T1041

T1041

Victims(56)

CompanyDomainCountryIndustryStatusDiscovered
aasa.ae
Claimed
in about 1 hour
www.mupras.com
Claimed
in about 1 hour
coemi.com.br
Claimed
in about 1 hour
www.courdescomptes.sncourdescomptes.snSN SenegalGovernment & Defense
Claimed
2 days ago
ersa.com.pyersa.com.pyPY ParaguayManufacturing
Claimed
2 days ago
theorangeblowfish.comtheorangeblowfish.comGB United KingdomTechnology
Claimed
4 days ago
frey.comfrey.comCH SwitzerlandTechnology
Claimed
5 days ago
www.mbt-energy.commbt-energy.comDE GermanyEnergy & Utilities
Claimed
7 days ago
aisem.gob.boaisem.gob.boBO BoliviaGovernment & Defense
Claimed
8 days ago
www.progress-security.comprogress-security.comDE GermanyTechnology
Claimed
8 days ago
libertyinsurance.com.phlibertyinsurance.com.phPH PhilippinesFinancial Services
Claimed
9 days ago
PROBE, S.A. DE C.VSV El SalvadorOther
Claimed
9 days ago
huashan.com.cnhuashan.com.cnCN ChinaManufacturing
Claimed
14 days ago
schultz.com.brschultz.com.brBR BrazilProfessional Services
Claimed
14 days ago
www.elumax.comelumax.comDE GermanyProfessional Services
Claimed
16 days ago
activ88-interim.comactiv88-interim.comDE GermanyProfessional Services
Claimed
17 days ago
www.transbras.com.gttransbras.com.gtGT GuatemalaTransportation
Claimed
17 days ago
tulipmediworld.comtulipmediworld.comIN IndiaHealthcare
Claimed
20 days ago
ecci-srl.comecci-srl.comIT ItalyProfessional Services
Claimed
21 days ago
motofrenos.commotofrenos.comMX MexicoManufacturing
Claimed
23 days ago

Page 1 of 3