Ransomware Group intelligence
Weyhro
InactiveTrack Weyhro with 14 published victims and 5 known leak locations in a single intelligence view.
Overview
Weyhro is tracked by Breach House as a ransomware group with 14 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Web location | Up checked 1h ago | weyhro.hk |
| Leak location 5 | Web location | Up checked 1h ago | weyhro.hk |
| Leak location 3 | Onion service | Down checked 1h ago | weyhro27ruifvuqkk3hxzcrtxv2lsalntxgkv6q2j3znkhdqudz54rqd.onion |
| Leak location 4 | Onion service | Down checked 1h ago | weyhro27ruifvuqkk3hxzcrtxv2lsalntxgkv6q2j3znkhdqudz54rqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | xtxtpqpyaaek4p4525ksepyyy75gfvi47fptm2gftw7cn656rnfhzdqd.onion |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Weyhro, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: weyhro executes malicious commands via PowerShell scripts to stage payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: weyhro leverages registry run keys to maintain persistence across system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: weyhro disables antivirus tools and security monitoring processes to evade detection during deployment.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: weyhro manipulates boot sequences to disable recovery mechanisms and enforce impact.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: weyhro encodes victim files with symmetric encryption keys before demanding ransom payments.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: weyhro deletes Volume Shadow Copies and backup directories via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: weyhro enumerates active network connections to identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: weyhro scans network shares using native tools to identify victim file structures and encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: weyhro moves laterally through SMB shares to compromise additional hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: weyhro encrypts victim files using custom ransomware binaries targeting critical business data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Victims (14)
Search, filter and paginate the victim timeline for Weyhro. Showing 1–14 of 14.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Community Services of Missouri id21662 View details | United States | Communication / Marketing | ||
|
[AI generated] Community Services of Missouri is an organization that provides a range of services to aid individuals and communities. These services include driver improvement programs, drug education and prevention programs, substance abuse traffic offender programs, and probation services. The organization focuses on fostering better understanding of safety, well-being, and responsible decision-making. Community Services of Missouri operates in various locations across the state of Missouri. |
|||||
| Ransomware | Chemtron RiverBend id21661 View details | United States | Communication / Marketing | ||
|
[AI generated] Chemtron RiverBend is a leading hazardous waste and non-hazardous waste management service provider. They specialize in providing effective and safe disposal and recycling of waste for a wide range of industries. They deliver waste management solutions with safety procedures and regulations, ensuring environmental protection and compliance. |
|||||
| Ransomware | Synergy Investments id20366 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] Synergy Investments is a prominent real estate investment firm. Established in 1997, it focuses on acquiring and revitalizing office properties in the Boston area. It manages over 30 buildings, combining for 4 million square feet of space. The company's philosophy centers around tenant satisfaction, proactive property management, and meticulous standard of operational excellence. |
|||||
| Ransomware | Terra Caribbean id20365 View details | Barbados | Construction / Real Estate | ||
|
[AI generated] Terra Caribbean is a real estate services company based in the Caribbean. They provide services across 14 territories including sales, rentals, land acquisition and commercial property management. With over 20 years of experience, Terra Caribbean offers expert knowledge about the property market in the region. They specialize in residential, commercial, and agricultural properties. |
|||||
| Ransomware | Adriatic Glass & Mirrors id20364 View details | Canada | Communication / Marketing | ||
|
[AI generated] Adriatic Glass & Mirrors is a company based in Ontario, Canada. They specialize in providing a variety of architectural glass products and related services. Some of the products offered include tempered glass, float glass, fire rated glass, and mirrored glass. They also offer glass installation services for commercial and residential projects. They're recognized for their commitment to quality and customer satisfaction. |
|||||
| Ransomware | 101 Arch Street id19943 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Valens Bank/Pay/Exchange id18873 View details | Germany | Finance / Legal / Insurance | ||
|
[AI generated] Valens Bank is a digital banking platform that offers private banking services to its clients worldwide. It provides services like multi-currency accounts, payment and transfer services, cryptocurrency trading, forex trading, and gold trading. Valens Pay facilitates global transfers, while Valens Exchange is a global market exchange platform. |
|||||
| Ransomware | McMillan James Equipment Company (MJEC) id18679 View details | United States | Communication / Marketing | ||
|
[AI generated] McMillan James Equipment Company (MJEC) specializes in providing end-to-end HVAC solutions for commercial and industrial applications. The company, headquartered in Texas, USA, offers a variety of services, including system design, equipment sales, installation, and maintenance. MJEC prides itself on implementing innovative technologies to improve indoor air quality and energy efficiency. |
|||||
| Ransomware | Montgomery Little & Soran, PC id18678 View details | United States | Services | ||
|
[AI generated] Montgomery Little & Soran, PC is a full-service law firm based in Greenwood Village, Colorado, offering legal services for areas such as Family Law, Real Estate, Business & Commercial, and Professional Liability. Their vast experience allows them to provide comprehensive solutions to businesses, professional organizations, individuals, and families. They have more than 40 attorneys specializing in different fields of law. |
|||||
| Ransomware | Central Electropolishing Company, Inc. id18235 View details | United States | Manufacturing / Engineering | ||
|
[AI generated] Central Electropolishing Company, Inc. (CELCO) is based in Arkansas, US. Since 1985, it has been doing electropolishing, which removes a thin layer of material from metal objects to make them smoother. They serve various industries including medical, food and beverage, and aerospace. Their services also include passivation and cleaning of various metal surfaces. |
|||||
| Ransomware | Resnick & Caffrey, PC id18234 View details | United States | Communication / Marketing | ||
|
[AI generated] Resnick & Caffrey, PC is a law firm that specializes in several areas of practice including estate planning, business law, and real estate. The firm consists of experienced attorneys who are dedicated to providing personalized and comprehensive legal advice. With a client-driven approach, they are known for efficiently delivering quality service. They believe in establishing strong relationships with their clients, understanding their needs, and providing strategic solutions. |
|||||
| Ransomware | Avantune Corporation id18233 View details | United States | IT | ||
|
[AI generated] Avantune Corporation is a technology company that specializes in self-service software and tools. The company's core product is Powua, a cloud automation platform designed for businesses to manage cloud infrastructure and resources efficiently. Avantune focuses on reducing the complexity of IT workloads and enhancing productivity by enabling autonomous IT operations. Founded in 2011, their headquarters are located in Miami, Florida, United States. |
|||||
| Ransomware | MBI International, Inc. id18232 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] MBI International, Inc. is a private investment firm based in the United States. It specializes in acquiring and developing companies in a variety of sectors, including real estate, retail, leisure, and technology. The firm often engages in partnerships with other companies and places an emphasis on innovative and high-growth potential businesses. MBI International, Inc. utilizes strategic planning and expert management to ensure the success of its investments. |
|||||
| Ransomware | Fragola S.p.A id18231 View details | Italy | Manufacturing / Engineering | ||
|
[AI generated] Fragola S.p.A is an Italian company well-known in the field of fluid power transmission systems. With roots dating back to 1900, the company specializes in engineering and manufacturing of standard and custom-made hydraulic fittings and systems. Fragola works across various industries, including construction, agriculture, marine, and aerospace, and offers targeted solutions to meet unique requirements. |
|||||