CiphBit is a crypto-ransomware first detected in April 2023. It utilizes a double-extortion model, encrypting files and threatening to leak stolen data via a Tor-hosted portal if ransom demands are not met. The malware appends encrypted files with a vector including a unique victim ID, the attacker’s email address (onionmail.org), and a four-character random extension—making file identification and recovery especially difficult. Victims span various sectors including banking, manufacturing, healthcare, logistics, and professional services across North America and Europe. The group is classified as a data broker due to its evolving extortion methods involving free leaks and selective leaks to pressure victims. Recent high-profile victims include iptelecom GmbH (Germany) and Therma Seal Insulation Systems (USA), reaffirming its cross-industry reach and impact.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
ciphbit ransomware
*/
rule ciphbit_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.ciphbit"
description = "Detects ciphbit ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "ciphbit" ascii nocase
$name2 = "CIPHBIT" ascii
$onion = "ciphbit.onion" ascii nocase
condition:
any of them
}
# CiphBit Locker All of Your Files And Network Have Been Strongly Secured By CiphBit Locker ! ################################## ## Your Decryption ID: [snip ] ## ################################## 1) Action Required: • Install Tor Browser via [redactado] • Enter CiphBit Tor Site: [redactado] • After Logging in, set your password and wait for the response. 2) Critical Instructions: • Do Not Modify or attempt to rename the encrypted files. This may lead to permanent data loss. • Do Not Share this information or breach details with any third party. This could be illogical. • You have a strict 48-hour window to take action. Failure to do so will result in the publication of your sensitive information on our blog, which may have serious consequences. 3) Additional Links: • CiphBit Tor Data Leak Blog: [redactado] • How To Buy Bitcoin: [redactado] • Tor Browser: [redactado]
[AI generated] N/A
[AI generated] N/A
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Clínica Villa Zaita | PA | Healthcare | — | 2 dic 2025 |
| Kitevuc - Equipamentos E Veiculo | BR | Not Found | — | 24 sept 2025 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética