CiphBit is an emerging ransomware threat actor observed in late 2023 and again among active ransomware groups affecting industrial organizations in Q1 2025. Public reporting places it among newer groups that appeared during a period of fragmentation in the ransomware ecosystem, when leak-site activity became more distributed across many operators rather than concentrated in a few dominant brands. CiphBit has been identified in victim-count reporting and group tracking, but high-confidence public detail on its internal structure, tooling, victimology, geographic origin, and specific intrusion tradecraft remains limited. Available reporting supports classifying CiphBit as a ransomware or extortion actor, but does not provide corroborated detail on whether it operates as a closed group or within a ransomware-as-a-service model, nor does it clearly document its preferred initial access vectors, post-compromise techniques, or use of encryption versus pure data-theft extortion. It has been listed alongside other newly observed ransomware brands during 2023 and 2025, indicating continued visibility in the criminal ransomware landscape, including reporting focused on industrial-sector victimization. No high-confidence attribution to a nation state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Emerging ransomware group listed as active in Q1 2025 targeting industrial sectors.
Ransomware group observed in Q3 2023 but not observed in Q4 2023 (per Dragos tracking of industrial-targeting ransomware).
Named as a newly observed ransomware group in September statistics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.