Ransomware Intelligence

krybit

Ransomware group profile

57Victims
74Impact score

Description

KryBit is a financially motivated ransomware group that emerged in March 2026, offering a Ransomware-as-a-Service model where affiliates retain a significant share of ransom payments. They employ a double-extortion strategy by encrypting files and exfiltrating sensitive data, with notable public conflicts with rival groups contributing to their visibility in the cybercriminal landscape.

Key insights

  • Utilizes a double-extortion model, encrypting files and stealing data.
  • Targets multiple operating systems, including Windows, Linux, and ESXi.
  • Ransom demands range between $40,000 to $100,000.
  • Employs complex evasion techniques, including shadow copy deletion and process injection.
  • Communicates with victims through Tor-based channels for negotiations.
  • Engages in inter-group conflicts that result in operational revelations.
  • Initial access often gained through phishing and exploited services.

Threat Level & Status Breakdown

For krybit · Based on incidents in selected period

3.7threat level
Aggressiveness9/ 10
Lethality0/ 10
Criticality1.8/ 10

Status Breakdown

Claimed100.0%57
First seenApr 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 23, 2026

Recent activity

Monthly attack count for krybit in the selected period

57Total attacks
24peak in Apr
19avg / month
↓ 6 vs first month
AprMayJun06121824

Intelligence

IOCs, YARA/Sigma rules, and related families for krybit

  1. oaptxiyisljt2kv3we2we34kuudmqda7f2geffoylzpeo7ourhtz4dad.onion
  2. zohlm7ahjwegcedoz7lrdrti7bvpofymcayotp744qhx6gjmxbuo2yid.onion
  3. krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion
View full IOC feed3 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for krybit

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1562

T1562

T1059

T1059

T1021

T1021

T1547

T1547

T1021.001

T1021.001

T1105

T1105

T1037

T1037

T1071

T1071

T1041

T1041

Victims(57)

CompanyDomainCountryIndustryStatusDiscovered
sansilvestre.edu.pesansilvestre.edu.pePE PeruEducation
Claimed
about 8 hours ago
aasa.aeaasa.aeAE United Arab EmiratesOther
Claimed
6 days ago
www.mupras.commupras.comBR BrazilProfessional Services
Claimed
6 days ago
coemi.com.brcoemi.com.brBR BrazilOther
Claimed
6 days ago
www.courdescomptes.sncourdescomptes.snSN SenegalGovernment & Defense
Claimed
8 days ago
ersa.com.pyersa.com.pyPY ParaguayManufacturing
Claimed
8 days ago
theorangeblowfish.comtheorangeblowfish.comGB United KingdomTechnology
Claimed
10 days ago
frey.comfrey.comCH SwitzerlandTechnology
Claimed
11 days ago
www.mbt-energy.commbt-energy.comDE GermanyEnergy & Utilities
Claimed
12 days ago
aisem.gob.boaisem.gob.boBO BoliviaGovernment & Defense
Claimed
14 days ago
www.progress-security.comprogress-security.comDE GermanyTechnology
Claimed
14 days ago
libertyinsurance.com.phlibertyinsurance.com.phPH PhilippinesFinancial Services
Claimed
15 days ago
PROBE, S.A. DE C.VSV El SalvadorOther
Claimed
15 days ago
huashan.com.cnhuashan.com.cnCN ChinaManufacturing
Claimed
20 days ago
schultz.com.brschultz.com.brBR BrazilProfessional Services
Claimed
20 days ago
www.elumax.comelumax.comDE GermanyProfessional Services
Claimed
22 days ago
activ88-interim.comactiv88-interim.comDE GermanyProfessional Services
Claimed
23 days ago
www.transbras.com.gttransbras.com.gtGT GuatemalaTransportation
Claimed
23 days ago
tulipmediworld.comtulipmediworld.comIN IndiaHealthcare
Claimed
26 days ago
ecci-srl.comecci-srl.comIT ItalyProfessional Services
Claimed
27 days ago

Page 1 of 3