Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

cry0 Ransomware Group

Ransomware group profile

4Victims
North KoreaSource country
54Impact score

Description

The ransomware group cry0 emerged in March 2026, using data broker tactics to engage in direct and double extortion. They are known for encrypting victim data while threatening to leak it through a dedicated leak site on TOR networks.

Key insights

  • Employs direct and double extortion tactics.
  • Utilizes a data leak site accessible via TOR networks.
  • Engages in threats to leak stolen information publicly.
  • Offers free portions of leaked data to entice compliance.
  • Targets a wide array of sectors, including healthcare and education.

Threat Level & Status Breakdown

For cry0 · Based on incidents in selected period

0.6threat level
Aggressiveness1.8/ 10
Lethality0/ 10
Criticality0/ 10

Status Breakdown

Claimed100.0%4
First seenMar 2026
Last seenSep 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 20, 2026

Recent activity

Monthly attack count for cry0 in the selected period

4Total attacks
1peak in Mar
1avg / month
MarJulAugSep00.250.50.751

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for cry0

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1059

T1059

T1562

T1562

T1021

T1021

T1547

T1547

T1021.001

T1021.001

T1080

T1080

T1027

T1027

Victims(3)

United StatesProfessional Servicesyounginjurylawnv.com
Claimed
2 days ago
United StatesRetail & E-Commercehopeswindows.com
Claimed
about 2 months ago
ItalyOtherdinisrl.it
Claimed
3 months ago