Ransomware Group intelligence
Krybit
ActiveTrack Krybit with 209 published victims and 6 known leak locations in a single intelligence view.
Overview
Krybit is tracked by Breach House as a ransomware group with 209 published victims.
Mexico is currently the most targeted country in this dataset.
6 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (6)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Up checked 5h ago | krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion |
| Leak location 5 | Onion service | Up checked 5h ago | krybieodq754vlwufrsuxaswxb5zpxyibaawmed2jaduoz2e5m56hmid.onion |
| Leak location 6 | Onion service | Up checked 5h ago | krybivdln3oc3twbin4budgznzq7dmcolldnsx455lspxxe23b56y5qd.onion |
| Leak location 3 | Onion service | Up checked 5h ago | krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion |
| Leak location 1 | Onion service | Up checked 5h ago | krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion |
| Leak location 2 | Web location | Down checked 5h ago | krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd. |
Top Activity Sectors (16)
- IT 20
- Manufacturing / Engineering 16
- Not identified 14
- Finance / Legal / Insurance 13
- Retail / E-commerce 9
- Transportation / Travel / Logistics 9
- Construction / Real Estate 8
- Healthcare / Pharma 7
- Public Sector 7
- Education 7
- Services 7
- Agriculture / Food 3
- Energy 3
- Hospitality / Food & Beverage / Tourism 2
- NGOs / Associations 2
- Telecommunications 2
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Krybit, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: krybit leverages PowerShell scripts to stage initial execution and automate lateral movement across endpoints.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: krybit uses native API calls to execute malicious payloads and bypass host-based execution controls.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: krybit modifies registry run keys to ensure malware persistence across reboots on compromised systems.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: krybit disables antivirus tools and security software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: krybit deletes Volume Shadow Copies and backup directories to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: krybit performs process discovery to identify critical services and isolate high-value targets for disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: krybit exploits SMB/Windows Admin Shares to move laterally within manufacturing and engineering networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: krybit exfiltrates stolen data over C2 channels before deployment to enable double extortion tactics.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: krybit encrypts victim files using custom ransomware routines, locking business data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: krybit invokes system recovery inhibition commands to prevent automated restoration of encrypted files.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-RECOVER.txt
--KRYBIT Your network/system was encrypted. Encrypted files have new extension. --Blog http://krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion/ http://krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion/ http://krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion/ http://krybieodq754vlwufrsuxaswxb5zpxyibaawmed2jaduoz2e5m56hmid.onion/ -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning If you modify files - our decrypt software won't able to recover data If you use third party software - you can damage/modify files (see item 1) You need cipher key / our decrypt software to restore you files. The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Visit the chat: http://krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion/chat/[snip]/ 3) Use this ID to log in: [snip] 4) Supp: 071EA649F06BDB7123C99653B7371E3B59860EE405E66A31EE0FD385F745A000405B6846ECBC
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (209)
Search, filter and paginate the victim timeline for Krybit. Showing 1–100 of 209.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ligacancerguate.org id32449 View details | Guatemala | Other | ||
|
ligacancerguate.org is cataloged as a ransomware victim within the Other sector, with operational or contextual association to the threat actor krybit. The entity reflects an organization affected by ransomware activity, documented within a threat-intelligence index for analytical and defensive reference. Details remain limited to the listing classification, sector designation, geographic context tied to Guatemala (GT), and the attributed threat actor. This entry supports cybersecurity professionals in tracking victim profiles, threat actor relationships, and sector-specific exposure patterns without asserting unverified incident details. It was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | ligacancerguate.org id32449 View details | Guatemala | Other | ||
|
INCAN — Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. is Guatemala's premier private cancer treatmen... |
|||||
| Ransomware | seashellhospital.com id32388 View details | India | Healthcare / Pharma | ||
|
seashellhospital.com operates within the healthcare and medicine sector, based in India. The entity represents a healthcare organization whose domain is cataloged within a threat-intelligence index as a ransomware victim linked to the threat actor krybit. This listing type identifies the relationship between the organization and the associated cyber threat actor without disclosing unverified incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics. The entry serves as a neutral reference point for monitoring healthcare infrastructure exposure to ransomware activity. The affected entity's inclusion underscores the critical need for vigilance among medical institutions against evolving cyber threats. |
|||||
| Ransomware | seashellhospital.com id32388 View details | India | Healthcare / Pharma | ||
|
Seashell Hospital is a comprehensive private Egyptian hospital located in New Cairo, Egypt, offering world-class multidi... |
|||||
| Ransomware | uicc.org id32389 View details | Switzerland | Public Sector | ||
|
uicc.org operates within the public sector and provides digital infrastructure and service-oriented offerings for governmental or institutional contexts. Its inclusion in this threat-intelligence index identifies it as a ransomware victim associated with the threat actor krybit. This listing reflects the entity's exposure within the cybersecurity incident landscape, contextualized by its sector and geographic origin country CH. The description remains neutral and avoids speculative details regarding compromised assets, data handling, or operational impact. Such catalog entries support threat analysts in mapping victimization patterns across sectors and regions. |
|||||
| Ransomware | uicc.org id32389 View details | Switzerland | Public Sector | ||
|
The Union for International Cancer Control (UICC) is the world's largest international cancer membership non-profit orga... |
|||||
| Ransomware | tum.com.mx id32390 View details | Mexico | Retail / E-commerce | ||
|
tum.com.mx operates within the retail and e-commerce sector based in Mexico, providing digital commerce services to customers and supporting business transactions in the consumer goods marketplace. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as krybit. The entry reflects the cybersecurity classification of the organization regarding its relationship to this threat actor without disclosing unverified incident details such as data stolen, records compromised, ransom demands, or confirmed breach specifics. The inclusion serves to inform defenders and analysts about potential exposure vectors within the retail and e-commerce sector in the Mexican market. It was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | tum.com.mx id32390 View details | Mexico | Retail / E-commerce | ||
|
TUM Transportistas Unidos Mexicanos División Norte, S.A. de C.V. is the largest trucking company in Mexico, founded in ... |
|||||
| Ransomware | www.alphaplantes.com id32391 View details | France | Agriculture / Food | ||
|
www.alphaplants.com operates within the Agriculture and Food sector and is located in France, providing business services aligned with food production and agricultural enterprise needs. This entity is listed within the threat-intelligence index under the designation ransomware victim, associated with threat actor krybit. The catalog entry reflects observed intelligence linking this organization to the ransomware activity attributed to krybit. No specific technical incident details, data exfiltration claims, ransom terms, or confirmed breach metrics are included to maintain factual neutrality and avoid invention. This listing serves threat-defense teams for contextual awareness regarding entities impacted by identified cyber threats. |
|||||
| Ransomware | www.alphaplantes.com id32391 View details | France | Agriculture / Food | ||
|
Alphaplantes (Service d'Entretien des Plantes Alpha Inc.) is a Canadian family-owned company founded in 1970, headquarte... |
|||||
| Ransomware | www.alphaplantes.com id32391 View details | Canada | Agriculture / Food | ||
|
Alphaplantes (Service d'Entretien des Plantes Alpha Inc.) is a Canadian family-owned company founded in 1970, headquarte... |
|||||
| Ransomware | reignwoodpark.com id32392 View details | China | Hospitality / Food & Beverage / Tourism | ||
|
reignwoodpark.com operates within the Hospitality, Food & Beverage, and Tourism sectors, serving guests and business partners in a location identified as China. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source designated as krybit. This classification reflects the cybersecurity event attributed to the organization without disclosing unverified technical findings, data scope, or financial impact. The record provides neutral context for threat researchers, defenders, and sector-focused security teams monitoring ransomware activity across hospitality and tourism environments. It was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | reignwoodpark.com id32392 View details | China | Hospitality / Food & Beverage / Tourism | ||
|
Reignwood Park Thailand is a luxury real estate and integrated lifestyle development project by Reignwood Group — a le... |
|||||
| Ransomware | orex.co.th id32376 View details | Thailand | IT | ||
|
orex.co.th is an entity situated in Thailand within the IT sector, identified through threat-intelligence indexing. The domain name suggests a digital service or organization operating within information technology services. It has been cataloged as a ransomware victim linked to the threat actor krybit. This listing type indicates that the entity was affected by ransomware activity attributed to krybit, reflecting a cybersecurity incident within its operational environment. The description remains neutral regarding specific technical details, incident specifics, or confirmed breach elements to maintain factual integrity and avoid speculation. |
|||||
| Ransomware | orex.co.th id32376 View details | Thailand | IT | ||
|
Orex Trading Co., Ltd. is a Thai trusted distributor and one-stop service provider of medical products, pharmaceuticals,... |
|||||
| Ransomware | amptc.net id32377 View details | United States | IT | ||
|
amptc.net operates within the IT sector based in the United States. The entity functions as a catalog entry within a threat-intelligence index, specifically categorized as a ransomware victim linked to the threat actor krybit. This listing type documents the entity's association with malicious activity in cybersecurity records. The description adheres to neutral, authoritative standards for threat-intelligence reporting, focusing on verified categorical associations without elaborating on unconfirmed incident details. It neutrally states that amptc.net was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | amptc.net id32377 View details | United States | IT | ||
|
Arab Maritime Petroleum Transport Company (AMPTC) is a leading Arab maritime shipping company established in 1972 as a s... |
|||||
| Ransomware | dmt-group.com id32378 View details | Germany | IT | ||
|
dmt-group.com operates within the IT sector and is associated with Germany (DE), with its domain context reflecting technology services and infrastructure activities. This entity is catalogued as a ransomware victim within the threat-intelligence index, specifically linked to the threat actor krybit. The listing type identifies the relationship between dmt-group.com and the ransomware incident associated with krybit without disclosing unverified technical or operational details. This entry provides neutral context for researchers tracking cyber threats, victim profiles, and actor-source associations across sectors and geographies. |
|||||
| Ransomware | dmt-group.com id32378 View details | Germany | IT | ||
|
DMT Consulting Private Limited is an Indian private limited company incorporated on September 25, 1998, formerly known a... |
|||||
| Ransomware | jswlaw.bt id32379 View details | Bhutan | Finance / Legal / Insurance | ||
|
jswlaw.bt operates within the Finance, Legal, and Insurance sectors and is documented as a ransomware victim within a threat-intelligence index. The entity is associated with threat actor krybit, indicating its inclusion reflects cybersecurity intelligence concerning ransomware activity targeting organizations in this geographic and industry context. Its sector profile highlights exposure risks common to regulated financial and legal services where operational continuity and data integrity are critical. This listing serves as a neutral reference point for threat analysts monitoring ransomware incidents across the Business and Technology region. The entity was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | jswlaw.bt id32379 View details | Bhutan | Finance / Legal / Insurance | ||
|
Jigme Singye Wangchuck School of Law (JSW Law) is Bhutan's first and only law school, established by Royal Charter on Fe... |
|||||
| Ransomware | vedantaainstitute.in id32380 View details | India | Education | ||
|
vedantaainstitute.in operates within the education sector based in India. The entity provides institutional services aligned with its domain identity, though specific operational details remain limited within publicly available threat-intelligence records. This listing type identifies vedantaainstitute.in as a ransomware victim within the threat-intelligence index. The association with threat actor krybit reflects the cybersecurity context in which the entity was cataloged. This description maintains factual neutrality regarding the incident without speculating on breach details, data impacts, or recovery specifics. |
|||||
| Ransomware | vedantaainstitute.in id32380 View details | India | Education | ||
|
Vedantaa Institute of Medical Sciences (VIMS) is a private Indian medical education institution and hospital operated un... |
|||||
| Ransomware | meccahighfeed.blogspot.com id32381 View details | Saudi Arabia | Other | ||
|
meccahighfeed.blogspot.com operates within the Other sector and is situated in Saudi Arabia. As documented in the threat-intelligence index, this entity is classified as a ransomware victim linked to the threat actor krybit. The listing type identifies the entity's involvement in ransomware activity without disclosing specific technical details, data loss specifics, or confirmed breach elements. This neutral catalog entry serves to contextualize the entity within cyber threat intelligence records, highlighting its association with krybit for analytical and monitoring purposes. |
|||||
| Ransomware | meccahighfeed.blogspot.com id32381 View details | Saudi Arabia | Other | ||
|
مصنع مكة وهاي فيد للأعلاف (Mecca High Feed Factory) is an Egyptian animal feed manufacturing compan... |
|||||
| Ransomware | transportesmontejo.com id32382 View details | Mexico | Transportation / Travel / Logistics | ||
|
transportesmontejo.com operates within the Transportation, Travel, and Logistics sector, serving regional and international freight and passenger movement services from Mexico. The entity functions as a commercial organization focused on mobility solutions, supply chain coordination, and related logistical operations across its geographic market. According to the threat-intelligence index, transportesmontejo.com is cataloged as a ransomware victim associated with the threat actor krybit. This classification reflects the cybersecurity event documented within the index without disclosing unverified technical details, data scope, or financial impact. The listing serves as a reference point for monitoring threat actor activity and sector-specific exposure in transportation environments. |
|||||
| Ransomware | transportesmontejo.com id32382 View details | Mexico | Transportation / Travel / Logistics | ||
|
Transportes Montejo S.A.S. is a Colombian specialized heavy transport and logistics company established on June 7, 1988,... |
|||||
| Ransomware | southsign.in id32383 View details | India | IT | ||
|
southsign.in is an entity operating within the IT sector based in India. The domain is cataloged as a ransomware victim within a threat-intelligence index, specifically associated with the threat actor krybit. This listing type indicates observed or attributed malicious activity linked to the entity's infrastructure or operations within cybersecurity monitoring frameworks. The description reflects the index classification without confirming specific incident details, data exposure, or operational impact. Neutral documentation supports threat-aware decision-making for security professionals and defenders monitoring IT sector risks in South Asian contexts. |
|||||
| Ransomware | southsign.in id32383 View details | India | IT | ||
|
Southsign Technologies is an Indian proprietor firm established in 2021, headquartered in Dindigul, Tamil Nadu, India, o... |
|||||
| Ransomware | hccd-construction.com id32384 View details | United States | Construction / Real Estate | ||
|
hccd-construction.com operates within the US construction and real estate sector, providing services aligned with infrastructure development and property management workflows. As a ransomware victim associated with threat actor krybit, this entity appears in the threat-intelligence index to document a cybersecurity incident affecting organizations in this specific industry and geographic region. The listing type identifies the relationship between the entity and the threat actor without disclosing unverified technical details or incident specifics. This catalog entry serves as a neutral reference point for analysts tracking cyber threats in construction and real estate environments. |
|||||
| Ransomware | hccd-construction.com id32384 View details | United States | Construction / Real Estate | ||
|
The Holding Company for Construction and Development (HCCD) is an Egyptian public holding company (Egyptian Holding Stoc... |
|||||
| Ransomware | finodayacapital.com id32149 View details | United States | Finance / Legal / Insurance | ||
|
FinodayAcapital.com operates within the Finance, Legal, and Insurance sectors and is headquartered in the United States. The entity provides financial advisory, capital management, and related professional services to clients within these regulated industries. As documented in the threat-intelligence index, FinodayAcapital.com is classified as a ransomware victim associated with the threat actor Krybit. This classification reflects cybersecurity event intelligence concerning the organization's exposure to malicious activity, without disclosing unverified incident details such as data stolen, ransom demands, or specific breach metrics. The listing serves to contextualize the entity's sector vulnerability and its documented relationship with the identified threat actor within the cybersecurity landscape. |
|||||
| Ransomware | finodayacapital.com id32149 View details | United States | Finance / Legal / Insurance | ||
|
Finodaya Capital Private Limited is an Indian tech-enabled Non-Banking Financial Company (NBFC) incorporated on Septembe... |
|||||
| Ransomware | cgcgabon.com id32150 View details | Gabon | Services | ||
|
cgcgabon.com operates within the Services sector and is located in Georgia. The entity is cataloged as a ransomware victim within this threat-intelligence index, with its association to the threat actor Krybit documented for cybersecurity monitoring and risk assessment purposes. This listing reflects observed threat-intelligence linkages rather than confirmed incident details, ensuring neutrality regarding specific attack vectors, data exposure, or operational impact. Understanding such associations supports defenders in identifying potential exposure patterns and contextualizing cyber threats across regional and sectoral boundaries. The entry serves as a reference point for threat analysts tracking ransomware activity and related actor behavior. |
|||||
| Ransomware | cgcgabon.com id32150 View details | Gabon | Services | ||
|
Le Conseil Gabonais des Chargeurs (CGC) is a Gabonese public administrative institution (établissement public à caract... |
|||||
| Ransomware | karkinos.in id32151 View details | India | IT | ||
|
karkinos.in operates within the IT sector and is situated in India. The entity is cataloged as a ransomware victim linked to the threat actor krybit. This listing reflects the organization's inclusion in a threat-intelligence index documenting ransomware-related incidents and associated actors. No specific incident details, such as stolen data, ransom demands, or confirmed breach metrics, are provided here to maintain factual neutrality. The profile serves to inform security professionals, analysts, and stakeholders about the entity's association with this threat actor within the cybersecurity landscape. |
|||||
| Ransomware | karkinos.in id32151 View details | India | IT | ||
|
Karkinos Healthcare Private Limited is an Indian comprehensive cancer care platform and healthcare technology company fo... |
|||||
| Ransomware | ferretornillos.gt id32152 View details | Guatemala | IT | ||
|
ferretornillos.gt operates within the IT sector and is situated in Guatemala (GT). The entity functions as a designated ransomware victim within the threat-intelligence index, explicitly linked to the threat actor krybit. Its inclusion reflects documented intelligence concerning cybersecurity incidents affecting this organization. The listing provides contextual data for analysts tracking ransomware campaigns, victim profiles, and associated threat actor methodologies across the technology sector. This entry serves to inform threat monitoring and risk assessment efforts without disclosing unverified incident details. |
|||||
| Ransomware | ferretornillos.gt id32152 View details | Guatemala | IT | ||
|
Ferretornillos, S.A. is a Guatemalan company incorporated on March 14, 2016, specializing in the wholesale distribution ... |
|||||
| Ransomware | www.sankovn.com id32153 View details | Viet Nam | IT | ||
|
www.sankovn.com operates within the IT sector and is situated in Vietnam. The entity is cataloged within this threat-intelligence index as a ransomware victim linked to the threat actor krybit. This listing type identifies the organization's role in documented cyber incidents involving ransomware activity. The entry provides contextual information for analysts tracking threat actor movements and victim profiles across sectors and geographies. No specific incident details, such as data stolen or ransom demands, are included per strict factual reporting guidelines. |
|||||
| Ransomware | www.sankovn.com id32153 View details | Viet Nam | IT | ||
|
Sanko Fastem (Vietnam) Co., Ltd. is a Vietnamese subsidiary of Sanko Fastem (Thailand) under the Sanko Techno Group (Jap... |
|||||
| Ransomware | www.neooftalmo.com.br id32159 View details | Brazil | Services | ||
|
www.neooftalmo.com.br operates within the Services sector based in Brazil (BR). The entity is cataloged in the threat-intelligence index as a ransomware victim linked to the threat actor Krybit. This listing type identifies the organization as having experienced ransomware activity connected to Krybit, reflecting its exposure within cybersecurity threat monitoring frameworks. The description focuses on verified intelligence context without disclosing unconfirmed incident details such as data stolen, ransom demands, or precise operational impacts. It serves to inform stakeholders of the entity's status within the ransomware victim index and its association with Krybit. |
|||||
| Ransomware | www.neooftalmo.com.br id32159 View details | Brazil | Services | ||
|
NEO — Núcleo de Excelência em Oftalmologia Ltda is a leading Brazilian ophthalmology hospital founded on May 13, 200... |
|||||
| Ransomware | lemonfarm.com id32160 View details | United States | Agriculture / Food | ||
|
lemonfarm.com operates within the Agriculture and Food sector and is located in the United States. The entity provides services aligned with agricultural and food production workflows, though specific operational details are not detailed in available threat intelligence records. According to the threat-intelligence index, lemonfarm.com is cataloged as a ransomware victim linked to the threat actor krybit. This listing reflects the association between the entity and the identified threat actor within the ransomware incident context. No additional incident specifics, such as data stolen, records impacted, ransom demands, or confirmed breach details, are provided to maintain factual neutrality and avoid speculation. |
|||||
| Ransomware | lemonfarm.com id32160 View details | United States | Agriculture / Food | ||
|
Lemon Farm Co., Ltd. is a leading Thai organic supermarket chain and online platform for organic and healthy food produc... |
|||||
| Ransomware | wmiemporium.com id32161 View details | United States | Retail / E-commerce | ||
|
wmiemporium.com is a US-based entity operating within the Retail and E-commerce sector, cataloged in this threat-intelligence index as a ransomware victim. The domain name and operational context align with retail and online commerce environments, where cyber incidents can disrupt customer transactions, inventory systems, and business continuity. This listing type identifies the entity as affected by ransomware activity associated with the threat actor krybit, reflecting the intelligence assessment of its exposure profile. The description remains factual and neutral, focusing on the entity's classification, sector, geographic origin, and the verified association with krybit without speculating on unconfirmed technical details or incident specifics. |
|||||
| Ransomware | wmiemporium.com id32161 View details | United States | Retail / E-commerce | ||
|
WMI Emporium Co., Ltd. is a Thai manufacturer and distributor of metal sheet products established in 2002 as a joint ven... |
|||||
| Ransomware | mimafoods.net id32162 View details | Brazil | Agriculture / Food | ||
|
mimafoods.net operates within the Agriculture and Food sector and is associated with the country Brazil. The entity represents a ransomware victim entry within a threat-intelligence index, where it is documented alongside threat actor krybit. This listing type indicates that mimafoods.net was identified as a target of ransomware activity tied to krybit, reflecting cybersecurity risk exposure in the food and agricultural business environment. The description remains factual and neutral, focusing on sector classification, geographic context, listing classification, and the associated threat actor without asserting unverified details about data theft, ransom demands, or confirmed breach specifics. It serves as catalog copy for researchers and defenders assessing ransomware exposure across critical infrastructure sectors. |
|||||
| Ransomware | mimafoods.net id32162 View details | Brazil | Agriculture / Food | ||
|
Mima Foods is an Egyptian top producer and global exporter of IQF (Individually Quick Frozen) frozen vegetables and food... |
|||||
| Ransomware | sysconth.com id32163 View details | Brazil | IT | ||
|
sysconth.com operates within the IT sector and is located in Brazil. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the associated threat actor krybit. This record documents the relationship between the organization and the identified threat actor without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. The entry provides neutral context for analysts monitoring ransomware activity in the IT sector across Brazil and related threat landscapes. It was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | sysconth.com id32163 View details | Brazil | IT | ||
|
Syscon (Thailand) Co., Ltd. is a Thai company headquartered in Bang Khen District, Bangkok, Thailand, specializing in th... |
|||||
| Ransomware | jindallifescience.com id32164 View details | India | Healthcare / Pharma | ||
|
Jindallife Science is an entity operating within the Healthcare and Pharma sector, based in India. The organization provides science-oriented services aligned with healthcare and pharmaceutical research and operational needs. According to the threat-intelligence index, this entity is cataloged as a ransomware victim associated with the threat actor krybit. This listing reflects the cybersecurity assessment linking the organization to this specific threat actor within the healthcare sector context. The entry documents the relationship without disclosing unverified incident details. |
|||||
| Ransomware | jindallifescience.com id32164 View details | India | Healthcare / Pharma | ||
|
Jindal Life Science Private Limited is an Indian full-service Contract Research Organization (CRO) established in 2023, ... |
|||||
| Ransomware | vascara.com id32165 View details | Brazil | Retail / E-commerce | ||
|
vascara.com operates within the retail and e-commerce sector, based in Brazil. The entity provides online commerce services and maintains digital infrastructure relevant to consumer transactions and business operations. According to the threat-intelligence index, vascara.com is cataloged as a ransomware victim associated with threat actor krybit. This listing type indicates a cybersecurity incident involving malicious software targeting the organization's digital assets. The description adheres to neutral reporting standards, focusing on verified entity attributes and the documented threat association without disclosing unconfirmed details about data handling, incident specifics, or resolution outcomes. |
|||||
| Ransomware | vascara.com id32165 View details | Brazil | Retail / E-commerce | ||
|
Vascara (Global Fashion One Member Company Limited) is a Vietnamese premium fashion brand specializing in stylish women'... |
|||||
| Ransomware | resi.com id32062 View details | Germany | IT | ||
|
resi.com operates within the IT sector and is situated in Germany. The entity is cataloged as a ransomware victim within this threat-intelligence index, linked to the threat actor Krybit. This listing type indicates a cybersecurity incident classification tied to ransomware activity involving the specified source. The description adheres to neutral, encyclopedic standards without inventing details regarding breach specifics, data handling, or recovery outcomes. The entry serves to document the entity's presence in threat intelligence records for analytical and defensive reference. |
|||||
| Ransomware | resi.com id32062 View details | Germany | IT | ||
|
Resi is a UK-based online architectural and home renovation platform founded in 2017 by Alexandra Depledge and Jules Col... |
|||||
| Ransomware | sunsea.co.th id31883 View details | Thailand | — | ||
|
Sunsea Plastics P.S. Co., Ltd. is a Thai family-owned company established in 1988, headquartered in Bang Na, Bangkok, Th... |
|||||
| Ransomware | www.mestojilemnice.cz id31899 View details | Czechia | — | ||
|
Město Jilemnice (City of Jilemnice) is the official website of the municipality of Jilemnice, a historic town located i... |
|||||
| Ransomware | automotoresrosedal.com.ar id31900 View details | Argentina | — | ||
|
Rosedal Automotores S.R.L. is an Argentine company incorporated on February 18, 2004, headquartered in the Las Cañitas ... |
|||||
| Ransomware | sipresitalia.it id31901 View details | Italy | — | ||
|
S.I.P.R.E.S. SRL (Società Italiana Progetti Ricerche e Sviluppo — Italian Research and Development Projects Company) ... |
|||||
| Ransomware | www.hsi.info id31902 View details | Hong Kong | — | ||
|
hsi personaldienste hart & schenk GmbH is a German staffing and temporary employment services company founded in Februar... |
|||||
| Ransomware | hisstw.com id31582 View details | Taiwan, Province of China | IT | ||
|
hisstw.com is an IT company based in Taiwan, providing various IT services. The company operates in the IT sector, offering a range of solutions. hisstw.com was listed as a ransomware victim associated with krybit |
|||||
| Ransomware | hisstw.com id31582 View details | Taiwan, Province of China | IT | ||
|
HISS Taroko Door & Window Technologies, Inc. (喜室清展股份有限公司) is a Taiwanese innovative R&D manufacturer... |
|||||
| Ransomware | labindia.com id31583 View details | India | Manufacturing / Engineering | ||
|
Labindia.com is a company based in India, operating in the manufacturing and engineering sector. The company likely offers various products and services related to laboratory equipment and engineering solutions. Labindia.com was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | labindia.com id31583 View details | India | Manufacturing / Engineering | ||
|
Labindia Instruments Pvt. Ltd. is an Indian private limited company founded in 1982 by a group of visionary technocrats ... |
|||||
| Ransomware | lhyk.com.sg id31584 View details | Singapore | Other | ||
|
lhyk.com.sg is a company based in Singapore, operating in the Other sector. The company's specific offerings are not well-documented, but it is known to be based in the country of Singapore. lhyk.com.sg was listed as a ransomware victim associated with krybit |
|||||
| Ransomware | lhyk.com.sg id31584 View details | Singapore | Other | ||
|
LHYK Marine Pte Ltd (Lee Huat Yap Kee) is a Singaporean marine logistics specialist company founded in 1959 and incorpor... |
|||||
| Ransomware | www.kilpi-koskinen.fi id31560 View details | Finland | Construction / Real Estate | ||
|
Kilpi-Koskinen is a company based in Finland, operating in the construction and real estate sector, providing various services to its clients. The company is involved in building and managing properties, and its operations are focused in Finland. Kilpi-Koskinen was listed as a ransomware victim associated with krybit |
|||||
| Ransomware | www.kilpi-koskinen.fi id31560 View details | Finland | Construction / Real Estate | ||
|
Kilpi-Koskinen Oy is a Finnish family-owned company founded on February 14, 1985, headquartered in Lahti, Finland, speci... |
|||||
| Ransomware | www.apsanet.com.ar id31561 View details | Argentina | IT | ||
|
Apsanet is an Argentine IT company providing various services. Located in Argentina, the company operates within the IT sector, offering services to its clients. Apsanet was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | www.apsanet.com.ar id31561 View details | Argentina | IT | ||
|
APSA Internacional S.A. is an Argentine company founded in 2001, part of Grupo Pintaluba (with Argentine and Spanish sha... |
|||||
| Ransomware | studiotibaldi.it id31485 View details | Italy | IT | ||
|
Studiotibaldi.it is an Italian company operating in the IT sector, providing various services. The company is based in Italy and offers solutions related to information technology. Studiotibaldi.it was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | studiotibaldi.it id31485 View details | Italy | IT | ||
|
Studio Associato Tibaldi is an Italian professional firm based in Rome, founded over 40 years ago, specializing in condo... |
|||||
| Ransomware | reflet2000.fr id31393 View details | France | Retail / E-commerce | ||
|
Reflet2000.fr operates in the retail and e-commerce sector in France, offering various products and services to its customers. As an e-commerce company, it provides online shopping experiences, likely catering to a wide range of consumer needs. Reflet2000.fr was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | reflet2000.fr id31393 View details | France | Retail / E-commerce | ||
|
REFLET 2000 is a French company founded in 1984, specializing in general building cleaning services (Nettoyage courant d... |
|||||
| Ransomware | www.actini.com id31394 View details | France | IT | ||
|
Actini is an IT company based in France, providing various services to its clients. The company operates in the IT sector, offering solutions to businesses. Actini was listed as a ransomware victim associated with krybit |
|||||
| Ransomware | www.actini.com id31394 View details | France | IT | ||
|
Actini Group (ACTINI SAS) is a French industrial machinery manufacturing company with over 70 years of experience, found... |
|||||
| Ransomware | www.ernat-bureau-etudes.fr id31395 View details | France | Manufacturing / Engineering | ||
|
Ernat Bureau Etudes is a French company operating in the manufacturing and engineering sector. The company provides various services and solutions to its clients. Ernat Bureau Etudes is listed as a ransomware victim associated with krybit |
|||||
| Ransomware | www.ernat-bureau-etudes.fr id31395 View details | France | Manufacturing / Engineering | ||
|
ERNAT (Etudes Réalisations Négoce Assistance Technique) SARL SCOP is a French worker cooperative (SCOP — Société C... |
|||||
| Ransomware | www.serengetiestates.co.za id31396 View details | South Africa | Construction / Real Estate | ||
|
Serengeti Estates is a South African company operating in the construction and real estate sector, providing various services to clients in the region. The company is involved in property development and management, catering to the needs of its customers in South Africa. Serengeti Estates was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | www.serengetiestates.co.za id31396 View details | South Africa | Construction / Real Estate | ||
|
Serengeti Estates (Serengeti Golf and Wildlife Estate) is a premier South African luxury residential golf and wildlife e... |
|||||
| Ransomware | www.hymiasa.com id31397 View details | Peru | Manufacturing / Engineering | ||
|
Hymiasa operates in the manufacturing and engineering sector in Peru, providing various products and services to its customers. As a company in this sector, it is involved in the design, development, and production of goods and equipment. Hymiasa was listed as a ransomware victim associated with krybit |
|||||
| Ransomware | www.hymiasa.com id31397 View details | Peru | Manufacturing / Engineering | ||
|
HYMIASA (Hules y Mangueras Industriales y Automotrices, S.A. de C.V.) is a Mexican leading company specialized in fluid ... |
|||||
| Ransomware | cesmac.edu.br id31239 View details | Brazil | Education | ||
|
Cesmac.edu.br is a Brazilian educational institution located in the country of Brazil, operating in the education sector, and offering various academic programs. The entity is involved in providing educational services to students. Cesmac.edu.br was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | cesmac.edu.br id31239 View details | Brazil | Education | ||
|
Centro Universitário CESMAC (CESMAC University Center) is the largest private higher education institution in the state... |
|||||
| Ransomware | www.prohealth.sg id31166 View details | Singapore | Healthcare / Pharma | ||
|
Prohealth.sg is a healthcare service provider based in Singapore, offering medical services to patients in the country. As a healthcare provider, prohealth.sg is part of the medicine sector in Singapore. Prohealth.sg was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | www.prohealth.sg id31166 View details | Singapore | Healthcare / Pharma | ||
|
ProHealth Medical Group Pte Ltd is a Singaporean private primary healthcare group founded in the 1990s, headquartered at... |
|||||
| Ransomware | www.dcpartner.co.za id31158 View details | South Africa | Finance / Legal / Insurance | ||
|
DC Partner is a financial and legal services company based in South Africa, operating in the finance, legal, and insurance sector. The company provides various services to its clients in these sectors. DC Partner was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | www.dcpartner.co.za id31158 View details | South Africa | Finance / Legal / Insurance | ||
|
DC Partner (Pty) Ltd is a South African market-leading Payment Distribution Agency (PDA), one of only four NCR-accredite... |
|||||
| Ransomware | nigeria.asa-international.com id31159 View details | Nigeria | Finance / Legal / Insurance | ||
|
Nigeria.asa-international.com operates in the finance, legal, and insurance sector in Nigeria, providing various financial services. The company's offerings cater to the Nigerian market, focusing on financial solutions. Nigeria.asa-international.com was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | nigeria.asa-international.com id31159 View details | Nigeria | Finance / Legal / Insurance | ||
|
ASHA Microfinance Bank Limited (ASA Nigeria) is a Nigerian for-profit deposit-taking microfinance institution, a fully l... |
|||||
| Ransomware | www.ville-rinxent.fr id31154 View details | France | Public Sector | ||
|
Ville Rinxent is a commune in the Pas-de-Calais department in the Hauts-de-France region of France, offering various public services to its residents. As a public sector entity, it provides essential services such as administrative support, infrastructure management, and community development. Ville Rinxent was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | www.ville-rinxent.fr id31154 View details | France | Public Sector | ||
|
Mairie de Rinxent (Municipality of Rinxent) is the official website of the town hall (mairie) of Rinxent, a small French... |
|||||
| Ransomware | countrymotors.com.mx id31155 View details | Mexico | Retail / E-commerce | ||
|
Countrymotors.com.mx is an e-commerce platform based in Mexico, operating in the retail sector, offering various products and services to its customers. As an online retailer, countrymotors.com.mx provides a range of products, catering to the Mexican market. Countrymotors.com.mx was listed as a ransomware victim associated with krybit |
|||||
| Ransomware | countrymotors.com.mx id31155 View details | Mexico | Retail / E-commerce | ||
|
Country Motos S.A. de C.V. (also known as Country Motors or Country Honda) is a Mexican motorcycle dealership and multi-... |
|||||
| Ransomware | www.buzztrading104.co.za id31157 View details | South Africa | Finance / Legal / Insurance | ||
|
Buzztrading104.co.za is a financial services entity based in South Africa, operating within the finance, legal, and insurance sector. The company likely provides various financial services to its clients in the region. It was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | www.buzztrading104.co.za id31157 View details | South Africa | Finance / Legal / Insurance | ||
|
Buzz Trading 104 (Pty) Ltd (also trading as Master Products) is a South African privately owned manufacturer and wholesa... |
|||||
| Ransomware | nilepet.com id30779 View details | Egypt | Energy | ||
|
Nilepet.com is an Egyptian energy company operating in the energy sector, providing various services and offerings to the industry. Located in Egypt, the company plays a significant role in the country's energy landscape. Nilepet.com was listed as a ransomware victim associated with krybit. |
|||||
| Ransomware | nilepet.com id30779 View details | Egypt | Energy | ||
|
Nile Petroleum Corporation (NILEPET) is the state-owned national oil and gas company of the Republic of South Sudan, est... |
|||||