Ransomware Group intelligence
Krybit
ActiveTrack Krybit with 234 published victims and 6 known leak locations in a single intelligence view.
Overview
Krybit is tracked by Dark Eye as a ransomware group with 234 published victims.
Mexico is currently the most targeted country in this dataset.
6 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 6 5.4%
- Pending 106 94.6%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (6)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Up checked 5h ago | krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion |
| Leak location 6 | Onion service | Up checked 5h ago | krybivdln3oc3twbin4budgznzq7dmcolldnsx455lspxxe23b56y5qd.onion |
| Leak location 5 | Onion service | Up checked 5h ago | krybieodq754vlwufrsuxaswxb5zpxyibaawmed2jaduoz2e5m56hmid.onion |
| Leak location 1 | Onion service | Up checked 5h ago | krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion |
| Leak location 3 | Onion service | Down checked 5h ago | krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion |
| Leak location 2 | Web location | Down checked 5h ago | krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd. |
Top Activity Sectors (16)
- IT 23
- Manufacturing / Engineering 17
- Not identified 16
- Finance / Legal / Insurance 14
- Transportation / Travel / Logistics 11
- Services 9
- Retail / E-commerce 9
- Construction / Real Estate 8
- Healthcare / Pharma 7
- Public Sector 7
- Education 7
- Hospitality / Food & Beverage / Tourism 4
- Agriculture / Food 3
- Energy 3
- NGOs / Associations 2
- Telecommunications 2
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Krybit, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: krybit leverages PowerShell scripts to stage initial execution and automate lateral movement across endpoints.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: krybit uses native API calls to execute malicious payloads and bypass host-based execution controls.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: krybit modifies registry run keys to ensure malware persistence across reboots on compromised systems.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: krybit disables antivirus tools and security software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: krybit deletes Volume Shadow Copies and backup directories to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: krybit performs process discovery to identify critical services and isolate high-value targets for disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: krybit exploits SMB/Windows Admin Shares to move laterally within manufacturing and engineering networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: krybit exfiltrates stolen data over C2 channels before deployment to enable double extortion tactics.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: krybit encrypts victim files using custom ransomware routines, locking business data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: krybit invokes system recovery inhibition commands to prevent automated restoration of encrypted files.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README-RECOVER.txt
--KRYBIT Your network/system was encrypted. Encrypted files have new extension. --Blog http://krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd.onion/ http://krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion/ http://krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion/ http://krybieodq754vlwufrsuxaswxb5zpxyibaawmed2jaduoz2e5m56hmid.onion/ -- Compromising and sensitive data We have downloaded compromising and sensitive data from you system/network If you refuse to communicate with us and we do not come to an agreement, your data will be published. Data includes: - Employees personal data, CVs, DL , SSN. - Complete network map including credentials for local and remote services. - Financial information including clients data, bills, budgets, annual reports, bank statements. - Complete datagrams/schemas/drawings for manufacturing in solidworks format - And more... -- Warning If you modify files - our decrypt software won't able to recover data If you use third party software - you can damage/modify files (see item 1) You need cipher key / our decrypt software to restore you files. The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions. -- Recovery 1) Download tor browser: https://www.torproject.org/download/ 2) Visit the chat: http://krybitx3fh5krdnhegyp2ob3lhizsaiadturtio3ginf7it5gsdgu2yd.onion/chat/[snip]/ 3) Use this ID to log in: [snip] 4) Supp: 071EA649F06BDB7123C99653B7371E3B59860EE405E66A31EE0FD385F745A000405B6846ECBC
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (234)
Search, filter and paginate the victim timeline for Krybit. Showing 1–100 of 234.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | www.kashkha.com id32798 View details | India | IT | pending | ||
|
Kashkha is a multinational modest fashion brand founded three decades ago in Dubai, UAE, specializing in designing, manu... |
||||||
| Ransomware | www.tiflispalace.ge id32773 View details | Georgia | Hospitality / Food & Beverage / Tourism | pending | ||
|
www.tiflispalace.ge represents a business operating within the Hospitality, Food & Beverage, and Tourism sectors located in Georgia (GE). The entity is cataloged in the threat-intelligence index under the designation of ransomware victim, with its associated threat actor identified as KRYBIT. This listing reflects the entity's inclusion in cybersecurity intelligence records documenting ransomware-related incidents affecting hospitality and tourism organizations in the region. No specific technical details, data breach specifics, or financial impact metrics are disclosed in this catalog entry, maintaining factual neutrality regarding the nature and scope of the incident. The record serves to inform threat analysts and security professionals about this entity's status within the indexed ransomware victim landscape. |
||||||
| Ransomware | www.tiflispalace.ge id32773 View details | Georgia | Hospitality / Food & Beverage / Tourism | pending | ||
|
Tiflis Palace is a luxurious boutique hotel located in the heart of Tbilisi, Georgia, in the legendary place of the city... |
||||||
| Ransomware | www.tender.mx id32774 View details | Mexico | Services | pending | ||
|
www.tender.mx operates within the Services sector and is situated in Mexico. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor krybit. This designation reflects the cybersecurity context in which the entity was identified within the index, highlighting exposure to ransomware activity linked to krybit. The description remains factual and neutral, focusing on the entity's classification, sector, geographic context, and its association with the named threat actor without elaborating on unverified incident details. This entry serves to inform stakeholders of the threat landscape context surrounding the entity. |
||||||
| Ransomware | www.tender.mx id32774 View details | Mexico | Services | pending | ||
|
Tender (Carnicería Tender) is a Mexican premium butcher shop chain (carnicería) founded under the original brand Vigar... |
||||||
| Ransomware | capricornlogistics.com id32775 View details | South Africa | Transportation / Travel / Logistics | pending | ||
|
capricornlogistics.com operates within the transportation, travel, and logistics sector, with operational presence indicated in South Africa (country: ZA). The entity functions as a logistics organization providing supply chain, freight, and related transportation services, though specific operational details beyond its sector classification are not publicly confirmed. This listing identifies capricornlogistics.com as a ransomware victim linked to the threat actor krybit, reflecting an incident context within cybersecurity intelligence monitoring. No verified specifics regarding data stolen, ransom demands, or breach confirmation are included per strict factual constraints. The record serves as a neutral reference point within the threat-intelligence index for tracking ransomware-related exposure in critical logistics infrastructure. |
||||||
| Ransomware | capricornlogistics.com id32775 View details | South Africa | Transportation / Travel / Logistics | pending | ||
|
Capricorn Logistics Pvt. Ltd. is an Indian comprehensive supply chain and logistics company founded in 2001 in Mumbai, M... |
||||||
| Ransomware | www.ibnsinatrust.com id32776 View details | United Arab Emirates | Finance / Legal / Insurance | pending | ||
|
www.ibnsinatrust.com operates within the Finance, Legal, and Insurance sectors and is situated in the country of the United Arab Emirates. The entity provides trust and assurance services aligned with its specialized industry focus, serving clients requiring security and compliance frameworks. This listing type identifies it as a ransomware victim within the threat-intelligence index, associated with the threat actor krybit. The catalog entry reflects the entity's classification based on verified intelligence sources without confirming specific incident details. Public disclosure status remains under review pending official confirmation from the entity itself. |
||||||
| Ransomware | www.ibnsinatrust.com id32776 View details | United Arab Emirates | Finance / Legal / Insurance | pending | ||
|
The Ibn Sina Trust is a pioneering Bangladeshi non-profit welfare trust and major healthcare provider founded on June 30... |
||||||
| Ransomware | lasultanahotels.com id32777 View details | Morocco | Hospitality / Food & Beverage / Tourism | pending | ||
|
lasultanahotels.com operates within the hospitality, food and beverage, and tourism sectors, serving the Mauritania market with lodging and travel-related services. The entity has been cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor krybit. This classification reflects observed threat-intelligence linkages without confirming specific breach details, data exfiltration scope, or operational impact. The inclusion underscores the vulnerability of hospitality organizations to cyber threats targeting sector-specific infrastructure. For threat analysts, this entry serves as a reference point within the krybit-associated ransomware victim index for monitoring and risk assessment. |
||||||
| Ransomware | lasultanahotels.com id32777 View details | Morocco | Hospitality / Food & Beverage / Tourism | pending | ||
|
La Sultana Hotel Group is a Moroccan luxury boutique hotel group created in the year 2000, targeting discerning traveler... |
||||||
| Ransomware | eracm.fr id32778 View details | France | IT | pending | ||
|
acm.fr is an entity identified within the IT sector located in France. Publicly available information describes it primarily through its domain identity and sector classification rather than through confirmed incident details. As cataloged in this threat-intelligence index, eracm.fr is listed as a ransomware victim associated with the threat actor krybit. This listing reflects the entity's relationship to the identified threat actor within the index's ransomware victim category. The description intentionally avoids inventing specifics such as breach scope, stolen data, ransom terms, or incident dates, relying only on the provided entity metadata and listing association. |
||||||
| Ransomware | eracm.fr id32778 View details | France | IT | pending | ||
|
ERACM (École Régionale d'Acteurs de Cannes et Marseille) is a French non-profit association and regional drama school ... |
||||||
| Ransomware | pss.ht id32779 View details | Haiti | Other | pending | ||
|
pss.ht is cataloged within the threat-intelligence index as a ransomware victim entity operating within the Other sector and associated with the threat actor krybit. The entity reflects cybersecurity monitoring activity concerning compromised or affected organizations, with contextual location data indicating HT as its associated country. Catalog entries of this nature provide neutral, structured intelligence for security professionals analyzing threat actor footprints, victim profiles, and sector-specific exposure patterns without disclosing unverified incident details. This listing type documents the relationship between pss.ht and krybit within the ransomware victim classification framework. |
||||||
| Ransomware | pss.ht id32779 View details | Haiti | Other | pending | ||
|
Professional Security Services S.A. (PSS) is a Haitian-owned private security services company established in 1995, head... |
||||||
| Ransomware | www.metalware.ca id32780 View details | Canada | Manufacturing / Engineering | pending | ||
|
www.metalware.ca is a Canadian entity operating within the Manufacturing and Engineering sector, providing specialized industrial and technical solutions for production, design, and operational workflows. The company's domain and operational profile place it within a high-value target category for cyber threats, particularly ransomware campaigns targeting industrial infrastructure. Within this threat-intelligence index, Metalware.ca is formally listed as a ransomware victim associated with the threat actor Krybit. This designation reflects the security event documented in the index and underscores the importance of monitoring cyber incidents across critical manufacturing and engineering sectors in Canada. The listing serves to inform stakeholders of the connection between this entity and the specified threat actor without disclosing unverified technical or operational details. |
||||||
| Ransomware | www.metalware.ca id32780 View details | Canada | Manufacturing / Engineering | pending | ||
|
Metalware Corporation Inc. is Canada's leading industrial shelving manufacturer, founded in 1954, headquartered in Montr... |
||||||
| Ransomware | intherpro.com id32781 View details | United States | IT | pending | ||
|
intherpro.com operates within the IT sector and is located in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as krybit. The description reflects the index classification only and does not assert confirmed breach details, stolen data, ransom terms, or specific incident evidence beyond the provided association. This entry supports threat-intelligence workflows by documenting victim-actor linkages across sectors and geographies. intherpro.com was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | intherpro.com id32781 View details | United States | IT | pending | ||
|
Intherpro LLC (International Thermal Insulation & Passive Fire Protection Company) is a UAE-based global leader in engin... |
||||||
| Ransomware | meridian16.hr id32782 View details | Croatia | Services | pending | ||
|
meridian16.hr is a Services sector entity located in Croatia (HR), cataloged within the threat-intelligence index as a ransomware victim. The entity operates within the services domain and its inclusion reflects threat-intelligence analysis linking it to the krybit threat actor. This listing type denotes an association with ransomware activity without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. The entry serves catalog and analytical purposes for monitoring threat actor behavior and victim profiles across sectors and geographies. It neutrally states that meridian16.hr was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | meridian16.hr id32782 View details | Croatia | Services | pending | ||
|
Meridian 16 Business Park d.o.o. is a Croatian eco-industrial business zone developer and operator, established over the... |
||||||
| Ransomware | www.eac-airports.com id32783 View details | Kenya | Transportation / Travel / Logistics | pending | ||
|
www.eac-airports.com operates within the Transportation, Travel, and Logistics sector, serving aviation and airport-related services and infrastructure functions. The entity is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor identified as Krybit. This listing reflects cybersecurity intelligence compiled regarding the organization's exposure to ransomware activity linked to this actor group. Details are presented neutrally to document the association without asserting unconfirmed breach specifics, data loss metrics, or operational impact beyond the indexed classification. The record supports threat-aware decision-making for sector stakeholders monitoring cybersecurity risks in global mobility ecosystems. |
||||||
| Ransomware | www.eac-airports.com id32783 View details | Kenya | Transportation / Travel / Logistics | pending | ||
|
Egyptian Airports Company (EAC) is an Egyptian state-owned public company incorporated in 2001, operating as a subsidiar... |
||||||
| Ransomware | swadeshicipl.com id32784 View details | India | Other | pending | ||
|
swadeshicipl.com operates within the Other sector and is situated in India. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as Krybit. This designation reflects its inclusion in cybersecurity intelligence records documenting ransomware-related incidents and actor attribution. The description remains factual and neutral, focusing on the entity's classification, geographic context, sector classification, and verified association with Krybit without extrapolating unconfirmed technical details or incident specifics. |
||||||
| Ransomware | swadeshicipl.com id32784 View details | India | Other | pending | ||
|
Swadeshi Civil Infrastructure Private Limited (SCIPL) is an Indian private limited company incorporated on March 11, 200... |
||||||
| Ransomware | ligacancerguate.org id32449 View details | Guatemala | Other | pending | ||
|
ligacancerguate.org is cataloged as a ransomware victim within the Other sector, with operational or contextual association to the threat actor krybit. The entity reflects an organization affected by ransomware activity, documented within a threat-intelligence index for analytical and defensive reference. Details remain limited to the listing classification, sector designation, geographic context tied to Guatemala (GT), and the attributed threat actor. This entry supports cybersecurity professionals in tracking victim profiles, threat actor relationships, and sector-specific exposure patterns without asserting unverified incident details. It was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | ligacancerguate.org id32449 View details | Guatemala | Other | pending | ||
|
INCAN — Instituto de Cancerología y Hospital Dr. Bernardo del Valle S. is Guatemala's premier private cancer treatmen... |
||||||
| Ransomware | seashellhospital.com id32388 View details | India | Healthcare / Pharma | pending | ||
|
seashellhospital.com operates within the healthcare and medicine sector, based in India. The entity represents a healthcare organization whose domain is cataloged within a threat-intelligence index as a ransomware victim linked to the threat actor krybit. This listing type identifies the relationship between the organization and the associated cyber threat actor without disclosing unverified incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics. The entry serves as a neutral reference point for monitoring healthcare infrastructure exposure to ransomware activity. The affected entity's inclusion underscores the critical need for vigilance among medical institutions against evolving cyber threats. |
||||||
| Ransomware | seashellhospital.com id32388 View details | India | Healthcare / Pharma | pending | ||
|
Seashell Hospital is a comprehensive private Egyptian hospital located in New Cairo, Egypt, offering world-class multidi... |
||||||
| Ransomware | uicc.org id32389 View details | Switzerland | Public Sector | pending | ||
|
uicc.org operates within the public sector and provides digital infrastructure and service-oriented offerings for governmental or institutional contexts. Its inclusion in this threat-intelligence index identifies it as a ransomware victim associated with the threat actor krybit. This listing reflects the entity's exposure within the cybersecurity incident landscape, contextualized by its sector and geographic origin country CH. The description remains neutral and avoids speculative details regarding compromised assets, data handling, or operational impact. Such catalog entries support threat analysts in mapping victimization patterns across sectors and regions. |
||||||
| Ransomware | uicc.org id32389 View details | Switzerland | Public Sector | pending | ||
|
The Union for International Cancer Control (UICC) is the world's largest international cancer membership non-profit orga... |
||||||
| Ransomware | tum.com.mx id32390 View details | Mexico | Retail / E-commerce | pending | ||
|
tum.com.mx operates within the retail and e-commerce sector based in Mexico, providing digital commerce services to customers and supporting business transactions in the consumer goods marketplace. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as krybit. The entry reflects the cybersecurity classification of the organization regarding its relationship to this threat actor without disclosing unverified incident details such as data stolen, records compromised, ransom demands, or confirmed breach specifics. The inclusion serves to inform defenders and analysts about potential exposure vectors within the retail and e-commerce sector in the Mexican market. It was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | tum.com.mx id32390 View details | Mexico | Retail / E-commerce | pending | ||
|
TUM Transportistas Unidos Mexicanos División Norte, S.A. de C.V. is the largest trucking company in Mexico, founded in ... |
||||||
| Ransomware | www.alphaplantes.com id32391 View details | France | Agriculture / Food | pending | ||
|
www.alphaplants.com operates within the Agriculture and Food sector and is located in France, providing business services aligned with food production and agricultural enterprise needs. This entity is listed within the threat-intelligence index under the designation ransomware victim, associated with threat actor krybit. The catalog entry reflects observed intelligence linking this organization to the ransomware activity attributed to krybit. No specific technical incident details, data exfiltration claims, ransom terms, or confirmed breach metrics are included to maintain factual neutrality and avoid invention. This listing serves threat-defense teams for contextual awareness regarding entities impacted by identified cyber threats. |
||||||
| Ransomware | www.alphaplantes.com id32391 View details | France | Agriculture / Food | pending | ||
|
Alphaplantes (Service d'Entretien des Plantes Alpha Inc.) is a Canadian family-owned company founded in 1970, headquarte... |
||||||
| Ransomware | www.alphaplantes.com id32391 View details | Canada | Agriculture / Food | pending | ||
|
Alphaplantes (Service d'Entretien des Plantes Alpha Inc.) is a Canadian family-owned company founded in 1970, headquarte... |
||||||
| Ransomware | reignwoodpark.com id32392 View details | China | Hospitality / Food & Beverage / Tourism | pending | ||
|
reignwoodpark.com operates within the Hospitality, Food & Beverage, and Tourism sectors, serving guests and business partners in a location identified as China. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source designated as krybit. This classification reflects the cybersecurity event attributed to the organization without disclosing unverified technical findings, data scope, or financial impact. The record provides neutral context for threat researchers, defenders, and sector-focused security teams monitoring ransomware activity across hospitality and tourism environments. It was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | reignwoodpark.com id32392 View details | China | Hospitality / Food & Beverage / Tourism | pending | ||
|
Reignwood Park Thailand is a luxury real estate and integrated lifestyle development project by Reignwood Group — a le... |
||||||
| Ransomware | orex.co.th id32376 View details | Thailand | IT | leaked | ||
|
orex.co.th is an entity situated in Thailand within the IT sector, identified through threat-intelligence indexing. The domain name suggests a digital service or organization operating within information technology services. It has been cataloged as a ransomware victim linked to the threat actor krybit. This listing type indicates that the entity was affected by ransomware activity attributed to krybit, reflecting a cybersecurity incident within its operational environment. The description remains neutral regarding specific technical details, incident specifics, or confirmed breach elements to maintain factual integrity and avoid speculation. |
||||||
| Ransomware | orex.co.th id32376 View details | Thailand | IT | leaked | ||
|
Orex Trading Co., Ltd. is a Thai trusted distributor and one-stop service provider of medical products, pharmaceuticals,... |
||||||
| Ransomware | amptc.net id32377 View details | United States | IT | pending | ||
|
amptc.net operates within the IT sector based in the United States. The entity functions as a catalog entry within a threat-intelligence index, specifically categorized as a ransomware victim linked to the threat actor krybit. This listing type documents the entity's association with malicious activity in cybersecurity records. The description adheres to neutral, authoritative standards for threat-intelligence reporting, focusing on verified categorical associations without elaborating on unconfirmed incident details. It neutrally states that amptc.net was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | amptc.net id32377 View details | United States | IT | pending | ||
|
Arab Maritime Petroleum Transport Company (AMPTC) is a leading Arab maritime shipping company established in 1972 as a s... |
||||||
| Ransomware | dmt-group.com id32378 View details | Germany | IT | pending | ||
|
dmt-group.com operates within the IT sector and is associated with Germany (DE), with its domain context reflecting technology services and infrastructure activities. This entity is catalogued as a ransomware victim within the threat-intelligence index, specifically linked to the threat actor krybit. The listing type identifies the relationship between dmt-group.com and the ransomware incident associated with krybit without disclosing unverified technical or operational details. This entry provides neutral context for researchers tracking cyber threats, victim profiles, and actor-source associations across sectors and geographies. |
||||||
| Ransomware | dmt-group.com id32378 View details | Germany | IT | pending | ||
|
DMT Consulting Private Limited is an Indian private limited company incorporated on September 25, 1998, formerly known a... |
||||||
| Ransomware | jswlaw.bt id32379 View details | Bhutan | Finance / Legal / Insurance | pending | ||
|
jswlaw.bt operates within the Finance, Legal, and Insurance sectors and is documented as a ransomware victim within a threat-intelligence index. The entity is associated with threat actor krybit, indicating its inclusion reflects cybersecurity intelligence concerning ransomware activity targeting organizations in this geographic and industry context. Its sector profile highlights exposure risks common to regulated financial and legal services where operational continuity and data integrity are critical. This listing serves as a neutral reference point for threat analysts monitoring ransomware incidents across the Business and Technology region. The entity was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | jswlaw.bt id32379 View details | Bhutan | Finance / Legal / Insurance | pending | ||
|
Jigme Singye Wangchuck School of Law (JSW Law) is Bhutan's first and only law school, established by Royal Charter on Fe... |
||||||
| Ransomware | vedantaainstitute.in id32380 View details | India | Education | pending | ||
|
vedantaainstitute.in operates within the education sector based in India. The entity provides institutional services aligned with its domain identity, though specific operational details remain limited within publicly available threat-intelligence records. This listing type identifies vedantaainstitute.in as a ransomware victim within the threat-intelligence index. The association with threat actor krybit reflects the cybersecurity context in which the entity was cataloged. This description maintains factual neutrality regarding the incident without speculating on breach details, data impacts, or recovery specifics. |
||||||
| Ransomware | vedantaainstitute.in id32380 View details | India | Education | pending | ||
|
Vedantaa Institute of Medical Sciences (VIMS) is a private Indian medical education institution and hospital operated un... |
||||||
| Ransomware | meccahighfeed.blogspot.com id32381 View details | Saudi Arabia | Other | pending | ||
|
meccahighfeed.blogspot.com operates within the Other sector and is situated in Saudi Arabia. As documented in the threat-intelligence index, this entity is classified as a ransomware victim linked to the threat actor krybit. The listing type identifies the entity's involvement in ransomware activity without disclosing specific technical details, data loss specifics, or confirmed breach elements. This neutral catalog entry serves to contextualize the entity within cyber threat intelligence records, highlighting its association with krybit for analytical and monitoring purposes. |
||||||
| Ransomware | meccahighfeed.blogspot.com id32381 View details | Saudi Arabia | Other | pending | ||
|
مصنع مكة وهاي فيد للأعلاف (Mecca High Feed Factory) is an Egyptian animal feed manufacturing compan... |
||||||
| Ransomware | transportesmontejo.com id32382 View details | Mexico | Transportation / Travel / Logistics | pending | ||
|
transportesmontejo.com operates within the Transportation, Travel, and Logistics sector, serving regional and international freight and passenger movement services from Mexico. The entity functions as a commercial organization focused on mobility solutions, supply chain coordination, and related logistical operations across its geographic market. According to the threat-intelligence index, transportesmontejo.com is cataloged as a ransomware victim associated with the threat actor krybit. This classification reflects the cybersecurity event documented within the index without disclosing unverified technical details, data scope, or financial impact. The listing serves as a reference point for monitoring threat actor activity and sector-specific exposure in transportation environments. |
||||||
| Ransomware | transportesmontejo.com id32382 View details | Mexico | Transportation / Travel / Logistics | pending | ||
|
Transportes Montejo S.A.S. is a Colombian specialized heavy transport and logistics company established on June 7, 1988,... |
||||||
| Ransomware | southsign.in id32383 View details | India | IT | pending | ||
|
southsign.in is an entity operating within the IT sector based in India. The domain is cataloged as a ransomware victim within a threat-intelligence index, specifically associated with the threat actor krybit. This listing type indicates observed or attributed malicious activity linked to the entity's infrastructure or operations within cybersecurity monitoring frameworks. The description reflects the index classification without confirming specific incident details, data exposure, or operational impact. Neutral documentation supports threat-aware decision-making for security professionals and defenders monitoring IT sector risks in South Asian contexts. |
||||||
| Ransomware | southsign.in id32383 View details | India | IT | pending | ||
|
Southsign Technologies is an Indian proprietor firm established in 2021, headquartered in Dindigul, Tamil Nadu, India, o... |
||||||
| Ransomware | hccd-construction.com id32384 View details | United States | Construction / Real Estate | pending | ||
|
hccd-construction.com operates within the US construction and real estate sector, providing services aligned with infrastructure development and property management workflows. As a ransomware victim associated with threat actor krybit, this entity appears in the threat-intelligence index to document a cybersecurity incident affecting organizations in this specific industry and geographic region. The listing type identifies the relationship between the entity and the threat actor without disclosing unverified technical details or incident specifics. This catalog entry serves as a neutral reference point for analysts tracking cyber threats in construction and real estate environments. |
||||||
| Ransomware | hccd-construction.com id32384 View details | United States | Construction / Real Estate | pending | ||
|
The Holding Company for Construction and Development (HCCD) is an Egyptian public holding company (Egyptian Holding Stoc... |
||||||
| Ransomware | finodayacapital.com id32149 View details | United States | Finance / Legal / Insurance | pending | ||
|
FinodayAcapital.com operates within the Finance, Legal, and Insurance sectors and is headquartered in the United States. The entity provides financial advisory, capital management, and related professional services to clients within these regulated industries. As documented in the threat-intelligence index, FinodayAcapital.com is classified as a ransomware victim associated with the threat actor Krybit. This classification reflects cybersecurity event intelligence concerning the organization's exposure to malicious activity, without disclosing unverified incident details such as data stolen, ransom demands, or specific breach metrics. The listing serves to contextualize the entity's sector vulnerability and its documented relationship with the identified threat actor within the cybersecurity landscape. |
||||||
| Ransomware | finodayacapital.com id32149 View details | United States | Finance / Legal / Insurance | pending | ||
|
Finodaya Capital Private Limited is an Indian tech-enabled Non-Banking Financial Company (NBFC) incorporated on Septembe... |
||||||
| Ransomware | cgcgabon.com id32150 View details | Gabon | Services | pending | ||
|
cgcgabon.com operates within the Services sector and is located in Georgia. The entity is cataloged as a ransomware victim within this threat-intelligence index, with its association to the threat actor Krybit documented for cybersecurity monitoring and risk assessment purposes. This listing reflects observed threat-intelligence linkages rather than confirmed incident details, ensuring neutrality regarding specific attack vectors, data exposure, or operational impact. Understanding such associations supports defenders in identifying potential exposure patterns and contextualizing cyber threats across regional and sectoral boundaries. The entry serves as a reference point for threat analysts tracking ransomware activity and related actor behavior. |
||||||
| Ransomware | cgcgabon.com id32150 View details | Gabon | Services | pending | ||
|
Le Conseil Gabonais des Chargeurs (CGC) is a Gabonese public administrative institution (établissement public à caract... |
||||||
| Ransomware | karkinos.in id32151 View details | India | IT | pending | ||
|
karkinos.in operates within the IT sector and is situated in India. The entity is cataloged as a ransomware victim linked to the threat actor krybit. This listing reflects the organization's inclusion in a threat-intelligence index documenting ransomware-related incidents and associated actors. No specific incident details, such as stolen data, ransom demands, or confirmed breach metrics, are provided here to maintain factual neutrality. The profile serves to inform security professionals, analysts, and stakeholders about the entity's association with this threat actor within the cybersecurity landscape. |
||||||
| Ransomware | karkinos.in id32151 View details | India | IT | pending | ||
|
Karkinos Healthcare Private Limited is an Indian comprehensive cancer care platform and healthcare technology company fo... |
||||||
| Ransomware | ferretornillos.gt id32152 View details | Guatemala | IT | pending | ||
|
ferretornillos.gt operates within the IT sector and is situated in Guatemala (GT). The entity functions as a designated ransomware victim within the threat-intelligence index, explicitly linked to the threat actor krybit. Its inclusion reflects documented intelligence concerning cybersecurity incidents affecting this organization. The listing provides contextual data for analysts tracking ransomware campaigns, victim profiles, and associated threat actor methodologies across the technology sector. This entry serves to inform threat monitoring and risk assessment efforts without disclosing unverified incident details. |
||||||
| Ransomware | ferretornillos.gt id32152 View details | Guatemala | IT | pending | ||
|
Ferretornillos, S.A. is a Guatemalan company incorporated on March 14, 2016, specializing in the wholesale distribution ... |
||||||
| Ransomware | www.sankovn.com id32153 View details | Viet Nam | IT | pending | ||
|
www.sankovn.com operates within the IT sector and is situated in Vietnam. The entity is cataloged within this threat-intelligence index as a ransomware victim linked to the threat actor krybit. This listing type identifies the organization's role in documented cyber incidents involving ransomware activity. The entry provides contextual information for analysts tracking threat actor movements and victim profiles across sectors and geographies. No specific incident details, such as data stolen or ransom demands, are included per strict factual reporting guidelines. |
||||||
| Ransomware | www.sankovn.com id32153 View details | Viet Nam | IT | pending | ||
|
Sanko Fastem (Vietnam) Co., Ltd. is a Vietnamese subsidiary of Sanko Fastem (Thailand) under the Sanko Techno Group (Jap... |
||||||
| Ransomware | www.neooftalmo.com.br id32159 View details | Brazil | Services | pending | ||
|
www.neooftalmo.com.br operates within the Services sector based in Brazil (BR). The entity is cataloged in the threat-intelligence index as a ransomware victim linked to the threat actor Krybit. This listing type identifies the organization as having experienced ransomware activity connected to Krybit, reflecting its exposure within cybersecurity threat monitoring frameworks. The description focuses on verified intelligence context without disclosing unconfirmed incident details such as data stolen, ransom demands, or precise operational impacts. It serves to inform stakeholders of the entity's status within the ransomware victim index and its association with Krybit. |
||||||
| Ransomware | www.neooftalmo.com.br id32159 View details | Brazil | Services | pending | ||
|
NEO — Núcleo de Excelência em Oftalmologia Ltda is a leading Brazilian ophthalmology hospital founded on May 13, 200... |
||||||
| Ransomware | lemonfarm.com id32160 View details | United States | Agriculture / Food | pending | ||
|
lemonfarm.com operates within the Agriculture and Food sector and is located in the United States. The entity provides services aligned with agricultural and food production workflows, though specific operational details are not detailed in available threat intelligence records. According to the threat-intelligence index, lemonfarm.com is cataloged as a ransomware victim linked to the threat actor krybit. This listing reflects the association between the entity and the identified threat actor within the ransomware incident context. No additional incident specifics, such as data stolen, records impacted, ransom demands, or confirmed breach details, are provided to maintain factual neutrality and avoid speculation. |
||||||
| Ransomware | lemonfarm.com id32160 View details | United States | Agriculture / Food | pending | ||
|
Lemon Farm Co., Ltd. is a leading Thai organic supermarket chain and online platform for organic and healthy food produc... |
||||||
| Ransomware | wmiemporium.com id32161 View details | United States | Retail / E-commerce | pending | ||
|
wmiemporium.com is a US-based entity operating within the Retail and E-commerce sector, cataloged in this threat-intelligence index as a ransomware victim. The domain name and operational context align with retail and online commerce environments, where cyber incidents can disrupt customer transactions, inventory systems, and business continuity. This listing type identifies the entity as affected by ransomware activity associated with the threat actor krybit, reflecting the intelligence assessment of its exposure profile. The description remains factual and neutral, focusing on the entity's classification, sector, geographic origin, and the verified association with krybit without speculating on unconfirmed technical details or incident specifics. |
||||||
| Ransomware | wmiemporium.com id32161 View details | United States | Retail / E-commerce | pending | ||
|
WMI Emporium Co., Ltd. is a Thai manufacturer and distributor of metal sheet products established in 2002 as a joint ven... |
||||||
| Ransomware | mimafoods.net id32162 View details | Brazil | Agriculture / Food | leaked | ||
|
mimafoods.net operates within the Agriculture and Food sector and is associated with the country Brazil. The entity represents a ransomware victim entry within a threat-intelligence index, where it is documented alongside threat actor krybit. This listing type indicates that mimafoods.net was identified as a target of ransomware activity tied to krybit, reflecting cybersecurity risk exposure in the food and agricultural business environment. The description remains factual and neutral, focusing on sector classification, geographic context, listing classification, and the associated threat actor without asserting unverified details about data theft, ransom demands, or confirmed breach specifics. It serves as catalog copy for researchers and defenders assessing ransomware exposure across critical infrastructure sectors. |
||||||
| Ransomware | mimafoods.net id32162 View details | Brazil | Agriculture / Food | leaked | ||
|
Mima Foods is an Egyptian top producer and global exporter of IQF (Individually Quick Frozen) frozen vegetables and food... |
||||||
| Ransomware | sysconth.com id32163 View details | Brazil | IT | pending | ||
|
sysconth.com operates within the IT sector and is located in Brazil. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the associated threat actor krybit. This record documents the relationship between the organization and the identified threat actor without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. The entry provides neutral context for analysts monitoring ransomware activity in the IT sector across Brazil and related threat landscapes. It was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | sysconth.com id32163 View details | Brazil | IT | pending | ||
|
Syscon (Thailand) Co., Ltd. is a Thai company headquartered in Bang Khen District, Bangkok, Thailand, specializing in th... |
||||||
| Ransomware | jindallifescience.com id32164 View details | India | Healthcare / Pharma | pending | ||
|
Jindallife Science is an entity operating within the Healthcare and Pharma sector, based in India. The organization provides science-oriented services aligned with healthcare and pharmaceutical research and operational needs. According to the threat-intelligence index, this entity is cataloged as a ransomware victim associated with the threat actor krybit. This listing reflects the cybersecurity assessment linking the organization to this specific threat actor within the healthcare sector context. The entry documents the relationship without disclosing unverified incident details. |
||||||
| Ransomware | jindallifescience.com id32164 View details | India | Healthcare / Pharma | pending | ||
|
Jindal Life Science Private Limited is an Indian full-service Contract Research Organization (CRO) established in 2023, ... |
||||||
| Ransomware | vascara.com id32165 View details | Brazil | Retail / E-commerce | pending | ||
|
vascara.com operates within the retail and e-commerce sector, based in Brazil. The entity provides online commerce services and maintains digital infrastructure relevant to consumer transactions and business operations. According to the threat-intelligence index, vascara.com is cataloged as a ransomware victim associated with threat actor krybit. This listing type indicates a cybersecurity incident involving malicious software targeting the organization's digital assets. The description adheres to neutral reporting standards, focusing on verified entity attributes and the documented threat association without disclosing unconfirmed details about data handling, incident specifics, or resolution outcomes. |
||||||
| Ransomware | vascara.com id32165 View details | Brazil | Retail / E-commerce | pending | ||
|
Vascara (Global Fashion One Member Company Limited) is a Vietnamese premium fashion brand specializing in stylish women'... |
||||||
| Ransomware | resi.com id32062 View details | Germany | IT | pending | ||
|
resi.com operates within the IT sector and is situated in Germany. The entity is cataloged as a ransomware victim within this threat-intelligence index, linked to the threat actor Krybit. This listing type indicates a cybersecurity incident classification tied to ransomware activity involving the specified source. The description adheres to neutral, encyclopedic standards without inventing details regarding breach specifics, data handling, or recovery outcomes. The entry serves to document the entity's presence in threat intelligence records for analytical and defensive reference. |
||||||
| Ransomware | resi.com id32062 View details | Germany | IT | pending | ||
|
Resi is a UK-based online architectural and home renovation platform founded in 2017 by Alexandra Depledge and Jules Col... |
||||||
| Ransomware | sunsea.co.th id31883 View details | Thailand | — | pending | ||
|
Sunsea Plastics P.S. Co., Ltd. is a Thai family-owned company established in 1988, headquartered in Bang Na, Bangkok, Th... |
||||||
| Ransomware | www.mestojilemnice.cz id31899 View details | Czechia | — | pending | ||
|
Město Jilemnice (City of Jilemnice) is the official website of the municipality of Jilemnice, a historic town located i... |
||||||
| Ransomware | automotoresrosedal.com.ar id31900 View details | Argentina | — | pending | ||
|
Rosedal Automotores S.R.L. is an Argentine company incorporated on February 18, 2004, headquartered in the Las Cañitas ... |
||||||
| Ransomware | sipresitalia.it id31901 View details | Italy | — | pending | ||
|
S.I.P.R.E.S. SRL (Società Italiana Progetti Ricerche e Sviluppo — Italian Research and Development Projects Company) ... |
||||||
| Ransomware | www.hsi.info id31902 View details | Hong Kong | — | pending | ||
|
hsi personaldienste hart & schenk GmbH is a German staffing and temporary employment services company founded in Februar... |
||||||
| Ransomware | hisstw.com id31582 View details | Taiwan, Province of China | IT | leaked | ||
|
hisstw.com is an IT company based in Taiwan, providing various IT services. The company operates in the IT sector, offering a range of solutions. hisstw.com was listed as a ransomware victim associated with krybit |
||||||
| Ransomware | hisstw.com id31582 View details | Taiwan, Province of China | IT | leaked | ||
|
HISS Taroko Door & Window Technologies, Inc. (喜室清展股份有限公司) is a Taiwanese innovative R&D manufacturer... |
||||||
| Ransomware | labindia.com id31583 View details | India | Manufacturing / Engineering | leaked | ||
|
Labindia.com is a company based in India, operating in the manufacturing and engineering sector. The company likely offers various products and services related to laboratory equipment and engineering solutions. Labindia.com was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | labindia.com id31583 View details | India | Manufacturing / Engineering | leaked | ||
|
Labindia Instruments Pvt. Ltd. is an Indian private limited company founded in 1982 by a group of visionary technocrats ... |
||||||
| Ransomware | lhyk.com.sg id31584 View details | Singapore | Other | leaked | ||
|
lhyk.com.sg is a company based in Singapore, operating in the Other sector. The company's specific offerings are not well-documented, but it is known to be based in the country of Singapore. lhyk.com.sg was listed as a ransomware victim associated with krybit |
||||||
| Ransomware | lhyk.com.sg id31584 View details | Singapore | Other | leaked | ||
|
LHYK Marine Pte Ltd (Lee Huat Yap Kee) is a Singaporean marine logistics specialist company founded in 1959 and incorpor... |
||||||
| Ransomware | www.kilpi-koskinen.fi id31560 View details | Finland | Construction / Real Estate | pending | ||
|
Kilpi-Koskinen is a company based in Finland, operating in the construction and real estate sector, providing various services to its clients. The company is involved in building and managing properties, and its operations are focused in Finland. Kilpi-Koskinen was listed as a ransomware victim associated with krybit |
||||||
| Ransomware | www.kilpi-koskinen.fi id31560 View details | Finland | Construction / Real Estate | pending | ||
|
Kilpi-Koskinen Oy is a Finnish family-owned company founded on February 14, 1985, headquartered in Lahti, Finland, speci... |
||||||
| Ransomware | www.apsanet.com.ar id31561 View details | Argentina | IT | pending | ||
|
Apsanet is an Argentine IT company providing various services. Located in Argentina, the company operates within the IT sector, offering services to its clients. Apsanet was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | www.apsanet.com.ar id31561 View details | Argentina | IT | pending | ||
|
APSA Internacional S.A. is an Argentine company founded in 2001, part of Grupo Pintaluba (with Argentine and Spanish sha... |
||||||
| Ransomware | studiotibaldi.it id31485 View details | Italy | IT | pending | ||
|
Studiotibaldi.it is an Italian company operating in the IT sector, providing various services. The company is based in Italy and offers solutions related to information technology. Studiotibaldi.it was listed as a ransomware victim associated with krybit. |
||||||
| Ransomware | studiotibaldi.it id31485 View details | Italy | IT | pending | ||
|
Studio Associato Tibaldi is an Italian professional firm based in Rome, founded over 40 years ago, specializing in condo... |
||||||
| Ransomware | reflet2000.fr id31393 View details | France | Retail / E-commerce | pending | ||
|
Reflet2000.fr operates in the retail and e-commerce sector in France, offering various products and services to its customers. As an e-commerce company, it provides online shopping experiences, likely catering to a wide range of consumer needs. Reflet2000.fr was listed as a ransomware victim associated with krybit. |
||||||