Ransomware Intelligence

krybit

Ransomware group profile

41Victims
69Impact score

Description

KryBit is a financially motivated ransomware group that emerged in March 2026, offering a Ransomware-as-a-Service model where affiliates retain a significant share of ransom payments. They employ a double-extortion strategy by encrypting files and exfiltrating sensitive data, with notable public conflicts with rival groups contributing to their visibility in the cybercriminal landscape.

Key insights

  • Utilizes a double-extortion model, encrypting files and stealing data.
  • Targets multiple operating systems, including Windows, Linux, and ESXi.
  • Ransom demands range between $40,000 to $100,000.
  • Employs complex evasion techniques, including shadow copy deletion and process injection.
  • Communicates with victims through Tor-based channels for negotiations.
  • Engages in inter-group conflicts that result in operational revelations.
  • Initial access often gained through phishing and exploited services.

Threat Level & Status Breakdown

For krybit · Based on incidents in selected period

3.8threat level
Aggressiveness9/ 10
Lethality0/ 10
Criticality2/ 10

Status Breakdown

Claimed100.0%41
First seenApr 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for krybit in the selected period

41Total attacks
24peak in Apr
13.7avg / month
↓ 22 vs first month
AprMayJun06121824

Intelligence

IOCs, YARA/Sigma rules, and related families for krybit

  1. oaptxiyisljt2kv3we2we34kuudmqda7f2geffoylzpeo7ourhtz4dad.onion
  2. zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion
  3. krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion
View full IOC feed3 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for krybit

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1562

T1562

T1059

T1059

T1021

T1021

T1547

T1547

T1021.001

T1021.001

T1105

T1105

T1037

T1037

T1071

T1071

T1041

T1041

Victims(41)

CompanyDomainCountryIndustryStatusDiscovered
activ88-interim.comactiv88-interim.comDE GermanyProfessional Services
Claimed
1 day ago
www.transbras.com.gttransbras.com.gtGT GuatemalaTransportation
Claimed
1 day ago
tulipmediworld.comtulipmediworld.comIN IndiaHealthcare
Claimed
4 days ago
ecci-srl.comecci-srl.comIT ItalyProfessional Services
Claimed
5 days ago
motofrenos.commotofrenos.comMX MexicoManufacturing
Claimed
7 days ago
smile-siam.comsmile-siam.comTH ThailandRetail & E-Commerce
Claimed
7 days ago
ctps.tp.edu.twctps.tp.edu.twTW TaiwanEducation
Claimed
8 days ago
bangkok.go.thbangkok.go.thTH ThailandGovernment & Defense
Claimed
11 days ago
lasevillanita.comlasevillanita.comES SpainHospitality
Claimed
12 days ago
SARL CANIS EVENTS SÉCURITÉ PRIVÉEFR FranceProfessional Services
Claimed
15 days ago
nacs.com.hknacs.com.hkHK Hong KongOther
Claimed
15 days ago
mindmastersg.commindmastersg.comSG SingaporeProfessional Services
Claimed
15 days ago
wwag.orgwwag.orgAT AustriaOther
Claimed
19 days ago
eclagestio360.comeclagestio360.comES SpainProfessional Services
Claimed
25 days ago
ovextech.comUS United StatesTechnology
Claimed
29 days ago
foodsmart.com.doDO Dominican RepublicManufacturing
Claimed
30 days ago
bomuhospital.orgbomuhospital.orgKE KenyaHealthcare
Claimed
about 1 month ago
weiss-pm.deweiss-pm.deDE GermanyProfessional Services
Claimed
about 1 month ago
zsiclife.co.zmZM ZambiaFinancial Services
Claimed
about 1 month ago
moser-spiel.atAT AustriaHospitality
Claimed
about 1 month ago

Page 1 of 3