Quick Summary
AllegedExecutive Summary
Krybit ransomware has claimed DMT Consulting Private Limited as a victim, with the listing appearing on September 1, 2026. SOCRadar’s Dark Web Monitoring identified this claim. DMT Consulting is a German-based engineering and technical consulting firm that provides specialized technology services across various sectors. The nature of its work, involving technology and consulting, makes it a potential target for ransomware and extortion activities due to the sensitive data it likely handles. In the 60 days preceding this listing, Krybit claimed 58 other victims. The group’s typical targeting focuses on Professional Services, Other, and Technology industries, with a geographic concentration in India, Thailand, and Brazil. Previous victims in the technology and consulting sectors include Arab Maritime Petroleum Transport Company, Syscon (Thailand) Co., Ltd., and Actini Group. DMT Consulting’s inclusion aligns with Krybit’s established targeting patterns within the technology and business services sectors.
Technical Analysis
A query for stealer-log records associated with the domain dmt-group[.]com revealed 26 records spanning from June 2024 to August 2026. Of these, 16 were identified as employee credentials. The queried endpoints include Autodesk (a design and collaboration platform common in engineering), pims.dmt-group[.]com (an internal project management system), and testdust.dmt-group[.]com (a test/staging environment). This extensive credential exposure over a 14-month period, without evidence of rotation, presents a significant corporate intrusion risk. The presence of multiple distinct corporate usernames appearing repeatedly across Autodesk and internal systems over this 14-month window, without any indication of credential rotation between June 2024 and August 2026, suggests a prolonged period of potential unauthorized access. For an engineering consultancy, access to platforms like Autodesk implies access to sensitive design files, client project data, and collaboration records. This prolonged credential exposure window is sufficient for extensive data exfiltration prior to the ransomware listing. The immediate recommendation is to rotate all Autodesk and PIMS credentials without delay. Furthermore, a thorough review of access logs from June 2024 onward is advised, with a specific focus on any unusual bulk file download or export activity. Continued monitoring of dark web and stealer-log feeds for the dmt-group[.]com domain and associated entities is also recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.