Ransomware Intelligence

cry0 Ransomware Group

Ransomware group profile

3Victims
North KoreaSource country
51Impact score

Description

The ransomware group cry0 emerged in March 2026, using data broker tactics to engage in direct and double extortion. They are known for encrypting victim data while threatening to leak it through a dedicated leak site on TOR networks.

Key insights

  • Employs direct and double extortion tactics.
  • Utilizes a data leak site accessible via TOR networks.
  • Engages in threats to leak stolen information publicly.
  • Offers free portions of leaked data to entice compliance.
  • Targets a wide array of sectors, including healthcare and education.

Threat Level & Status Breakdown

For cry0 · Based on incidents in selected period

0.6threat level
Aggressiveness1.8/ 10
Lethality0/ 10
Criticality0/ 10

Status Breakdown

Claimed100.0%3
First seenMar 2026
Last seenAug 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 8, 2026

Recent activity

Monthly attack count for cry0 in the selected period

3Total attacks
1peak in Mar
1avg / month
MarJulAug00.250.50.751

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for cry0

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1059

T1059

T1562

T1562

T1021

T1021

T1547

T1547

T1021.001

T1021.001

T1080

T1080

T1027

T1027

Victims(3)

United StatesRetail & E-Commercehopeswindows.com
Claimed
3 days ago
ItalyOtherdinisrl.it
Claimed
about 1 month ago
ItalyTransportationdinisrl.it
Claimed
4 months ago