Ransomware Group intelligence
Krybit
ActiveTrack Krybit with 209 published victims and 6 known leak locations in a single intelligence view.
Overview
Krybit is tracked by Breach House as a ransomware group with 209 published victims.
Mexico is currently the most targeted country in this dataset.
6 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (6)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Up checked 4h ago | krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion |
| Leak location 5 | Onion service | Up checked 4h ago | krybieodq754vlwufrsuxaswxb5zpxyibaawmed2jaduoz2e5m56hmid.onion |
| Leak location 6 | Onion service | Up checked 4h ago | krybivdln3oc3twbin4budgznzq7dmcolldnsx455lspxxe23b56y5qd.onion |
| Leak location 3 | Onion service | Up checked 4h ago | krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion |
| Leak location 1 | Onion service | Up checked 4h ago | krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion |
| Leak location 2 | Web location | Down checked 4h ago | krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd. |
Top Activity Sectors (16)
- IT 20
- Manufacturing / Engineering 16
- Not identified 14
- Finance / Legal / Insurance 13
- Retail / E-commerce 9
- Transportation / Travel / Logistics 9
- Construction / Real Estate 8
- Healthcare / Pharma 7
- Public Sector 7
- Education 7
- Services 7
- Agriculture / Food 3
- Energy 3
- Hospitality / Food & Beverage / Tourism 2
- NGOs / Associations 2
- Telecommunications 2
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Krybit, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: krybit leverages PowerShell scripts to stage initial execution and automate lateral movement across endpoints.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: krybit uses native API calls to execute malicious payloads and bypass host-based execution controls.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: krybit modifies registry run keys to ensure malware persistence across reboots on compromised systems.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: krybit disables antivirus tools and security software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: krybit deletes Volume Shadow Copies and backup directories to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: krybit performs process discovery to identify critical services and isolate high-value targets for disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: krybit exploits SMB/Windows Admin Shares to move laterally within manufacturing and engineering networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: krybit exfiltrates stolen data over C2 channels before deployment to enable double extortion tactics.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: krybit encrypts victim files using custom ransomware routines, locking business data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: krybit invokes system recovery inhibition commands to prevent automated restoration of encrypted files.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-RECOVER.txt
--KRYBIT Your network/system was encrypted. Encrypted files have new extension. --Blog http://krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion/ http://krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion/ http://krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion/ http://krybieodq754vlwufrsuxaswxb5zpxyibaawmed2jaduoz2e5m56hmid.onion/ -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning If you modify files - our decrypt software won't able to recover data If you use third party software - you can damage/modify files (see item 1) You need cipher key / our decrypt software to restore you files. The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Visit the chat: http://krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion/chat/[snip]/ 3) Use this ID to log in: [snip] 4) Supp: 071EA649F06BDB7123C99653B7371E3B59860EE405E66A31EE0FD385F745A000405B6846ECBC
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (209)
Search, filter and paginate the victim timeline for Krybit. Showing 201–209 of 209.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | conrepsa.ro id28075 View details | Romania | Construction / Real Estate | ||
|
CONREP SA is a Romanian construction, contracting, and infrastructure company, considered one of the most experienced in... |
|||||
| Ransomware | megasurf.co.za id28050 View details | South Africa | Telecommunications | ||
|
Megasurf is an internet service provider and data center operator specializing in high-speed fibre and wireless internet... |
|||||
| Ransomware | Gerald Zisser GmbH id27964 View details | Germany | Transportation / Travel / Logistics | ||
|
Gerald Zisser GmbH is a private Austrian company specializing in building technical services, focusing on plumbing, heat... |
|||||
| Ransomware | fraper.com id27943 View details | Spain | IT | ||
|
Comercial Fraper S.L. is a privately held Spanish company specializing in building materials, tools, and household suppl... |
|||||
| Ransomware | CCCKeito.edu.hk id27924 View details | Hong Kong | Education | ||
|
CCC Kei To Secondary School (中華基督教會基道中學) CCCKeito.edu.hk is the official website of this secondary ... |
|||||
| Ransomware | lkc.ac.bw id27885 View details | Botswana | Education | ||
|
Livingstone Kolobeng College (LKC) is a private educational institution located in Gaborone, the capital of Botswana . I... |
|||||
| Ransomware | BJ Grupo id27876 View details | Mexico | Transportation / Travel / Logistics | ||
|
BJ Grupo operates in the fuel and lubricating oil distribution sector throughout the state of São Paulo. The company of... |
|||||
| Ransomware | kramer-nsc.at id27875 View details | Austria | IT | ||
|
Kramer Nutzfahrzeug Service Center GmbH specializes in the service and repair of commercial vehicles, including brands l... |
|||||
| Ransomware | whiskey.co.jp id27874 View details | Japan | IT | ||
|
Whiskey & Co., Inc. (in Japanese: Whiskey & Co.株式会社) is a modern Japanese company founded on January 28, 2021. I... |
|||||