Ransomware Group intelligence
Cryp70n1c0d3
InactiveTrack Cryp70n1c0d3 with 11 published victims and 1 known leak locations in a single intelligence view.
Overview
Cryp70n1c0d3 is tracked by Breach House as a ransomware group with 11 published victims.
India is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 25m ago | 7k4yyskpz3rxq5nyokf6ztbpywzbjtdfanweup3skctcxopmt7tq7eid.onion |
Top Activity Sectors (3)
- Not identified 9
- Education 1
- IT 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Cryp70n1c0d3, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: cryp70n1c0d3 executes PowerShell scripts to deliver payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: cryp70n1c0d3 disables security tools like antivirus software to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: cryp70n1c0d3 deletes Volume Shadow Copies and backup files to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: cryp70n1c0d3 brute-forces local accounts to gain initial access to victim systems.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1083 File and Directory Discovery Discovery
What they do: cryp70n1c0d3 scans file and directory structures to identify targets for encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: cryp70n1c0d3 moves laterally via SMB/Windows Admin Shares across networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: cryp70n1c0d3 encrypts victim files using a custom ransomware payload to hold data hostage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: cryp70n1c0d3 stops critical Windows services to disrupt host functionality during impact.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: cryp70n1c0d3 runs commands to inhibit system recovery processes after encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (11)
Search, filter and paginate the victim timeline for Cryp70n1c0d3. Showing 1–11 of 11.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | iima.ac.in id2201 View details | India | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | hislopcollege.ac.in id2200 View details | India | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | oppodigital.in id2199 View details | India | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | nals.in id2198 View details | India | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | albatross.co.in id2197 View details | India | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | suriyanar.com id2196 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shinyoko-porno.com id2195 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | toxicsites.us id2194 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | antistatik-esd-cozumler.com.tr id2193 View details | Türkiye | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | paknavy.gov.pk id2192 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | vaja.ir id2191 View details | Other | — | ||
|
No additional victim description available. |
|||||