Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
krybit ransomware
*/
rule krybit_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.krybit"
description = "Detects krybit ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "krybit" ascii nocase
$name2 = "KRYBIT" ascii
$onion = "krybit.onion" ascii nocase
condition:
any of them
}
--KRYBIT Your network/system was encrypted. Encrypted files have new extension. --Blog [redactado] [redactado] [redactado] [redactado] -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning If you modify files - our decrypt software won't able to recover data If you use third party software - you can damage/modify files (see item 1) You need cipher key / our decrypt software to restore you files. The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: [redactado] 2) Visit the chat: [redactado] 3) Use this ID to log in: [snip] 4) Supp: [redactado]
Lumax is dedicated to maintaining high standards of ethics, corporate governance and effective accountability mechanisms...
Activ'Interim 88 was founded in 2008 with the aim of connecting job seekers with the best opportunities available in the...
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| www.elumax.com | DE | Business Services | — | 3 jun 2026 |
| activ88-interim.com | DE | Business Services | — | 2 jun 2026 |
| www.transbras.com.gt | GT | Transportation/Logistics | — | 2 jun 2026 |
| tulipmediworld.com | IN | Healthcare | — | 30 may 2026 |
| ecci-srl.com | IT | Business Services | — | 30 may 2026 |
| motofrenos.com | MX | Manufacturing | — | 27 may 2026 |
| smile-siam.com | TH | Consumer Services | — | 27 may 2026 |
| foodsmart.com.do | DO | Agriculture and Food Production | — | 5 may 2026 |
| asesoriauriel.com | MX | Business Services | — | 14 abr 2026 |
| secran.com.br | BR | Business Services | — | 14 abr 2026 |
| BJ Grupo | MX | Energy | — | 3 abr 2026 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética
Founded in 1974, started its activities in Road Transport, eventually expanding its services to several other areas, fir...
A complete data breach has occurred at Tulip Mediworld Hospital, a multi-specialty hospital located on GS Road, Rukmini ...
Empresa dedicada al rubro de construcción de proyectos inmobiliarios, particularmente la Ciudad Nueva Santa Cruz. El á...
MotoFrenos is a Colombian metalworking company with a global reach that designs, manufactures, and installs equipment an...